Hostnames
OpenHands serves these hostnames, usingopenhands.example.com as the base domain (matching the
Helm install):
All of these must resolve to your ingress load balancer. Every hostname sits one label under the
base domain, so a single wildcard DNS record and certificate for
*.openhands.example.com
cover everything, including the dynamically named sandboxes.
external-dns
external-dns watches your Ingresses and Services and creates the matching DNS records automatically.- Install it from its Helm chart.
- Set
providerto your DNS provider and grant it access to your zone (the access mechanism is provider-specific). - Recommended settings:
upsert-only and a TXT registry, external-dns only ever touches records it created.
cert-manager
cert-manager issues and renews certificates from Let’s Encrypt. Use the DNS-01 challenge, the only one that can issue wildcard certificates.1
Install cert-manager
Install it from its Helm chart, and grant it
access to your DNS provider so it can solve DNS-01 challenges.
2
Create a ClusterIssuer
The
solvers block is specific to your DNS provider. The Route 53 solver is shown here.3
Request a wildcard certificate
A single wildcard covers every hostname. With Traefik, serve it as the default
TLSStore so
no per-ingress TLS config is needed.Manual Setup
If you don’t run external-dns and cert-manager, provision these by hand and point the ingress controller at them. DNS: create a single wildcard record*.openhands.example.com pointing to your ingress load
balancer (typically a CNAME to the load balancer’s hostname, or a cloud DNS alias).
TLS: obtain a certificate with a *.openhands.example.com SAN and load it into the ingress
controller as a Kubernetes TLS secret.
If you can’t use a wildcard certificate, obtain one with SANs for the app, auth, and
runtime-api hostnames plus runtime.openhands.example.com, and set
runtime-api.env.RUNTIME_ROUTING_MODE: "path" in your Helm values so sandboxes are served under
runtime.openhands.example.com/<id> instead of their own hostnames.
Next Steps
Installing Sysbox
Install the sandbox runtime on your sandbox nodes.
Install with Helm
Deploy OpenHands once the cluster is ready.

