Automatic TLS
Every domain on Orizon — the free subdomain, your connected domains, and anything you buy — is served over HTTPS with a certificate Orizon obtains and renews for you.
How it works
Orizon serves your apps behind Caddy, which has a built-in ACME client. When a domain's DNS resolves to Orizon, Caddy automatically requests a certificate from Let's Encrypt, installs it, and serves your app over HTTPS. There's nothing to upload and no CSR to generate.
Renewal
Certificates are renewed automatically well before they expire, so HTTPS keeps working indefinitely without any action from you.
Cloudflare-proxied domains
If your domain is proxied through Cloudflare, set it to DNS-only for the initial issuance so the challenge can reach Orizon, then proxy it again if you like. The domain view shows whether a domain is currently proxied.