Skip to main content
Glama

Create a Domain

create_domain

Put a domain in front of a workload: pass domain, workload, and gvc, and the 443 listener, its route, and cname mode are derived; the result lists the DNS records the user must add, and the same call with waitSeconds reports when it is ready (an existing domain gets the route added). For a custom setup (other listeners, ns delegation, gvcLink, several routes) pass dnsMode and ports instead; a port item is {number, protocol}, a route needs workloadLink and matches / without prefix.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
gvcNoThe workload's GVC.
orgNoOrganization slug.
tagsNoOptional tags; they behave like Kubernetes labels. Special behavior-changing tags: cpln/routeLimitOverride (raises the per-port route cap to 200), cpln/skipDNSCheck, cpln/wildcard (wildcard certificate).
portsNoListener list; derived with workload, required otherwise. Each listener needs number and protocol; cors, routes, and tls are optional.
domainYesFully qualified domain name such as example.com or api.example.com.
prefixNoPath prefix the derived route matches (default "/"). With workload only.
dnsModeNoDNS delegation mode; derived (cname) with workload. cname works for an apex (example.com) and subdomains; ns delegates a subdomain zone to Control Plane and is rejected on an apex.
gvcLinkNoOptional GVC link (full or shorthand //gvc/{name}). Each workload in the GVC gets a {workload}.{domain} subdomain. Mutually exclusive with workloadLink.
workloadNoRoute the domain to this workload (with gvc): the 443 listener, its route, and dnsMode cname are derived.
descriptionNoDomain description so operators understand the purpose (treat it like a concise annotation).
waitSecondsNoSeconds to wait on the server until the domain is ready, 0 to 45. The call returns as soon as it is, or with the latest state when the time runs out. Use this instead of calling again and again.
workloadLinkNoOptional workload link (e.g. //gvc/{gvc}/workload/{name}) to bind the ENTIRE domain to one workload — STATEFUL workloads only (the platform rejects serverless/standard here). For those, target the workload with ports[].routes instead. Mutually exclusive with gvcLink.
acceptAllHostsNoAccept any host header (defaults to false).
certChallengeTypeNoCertificate challenge type (http01 or dns01). Optional — omit for the platform default, and MUST be omitted for .internal domains (the platform rejects it there).
acceptAllSubdomainsNoAccept any subdomain (defaults to false).

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
okYes
dataNoThe full result. Read this, not only the summary.
detailsNo
summaryYes
nextStepsNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changed
    • addedInput schema / properties / ports / items / properties / routes / items / properties / caseInsensitive
      Added value: +{
      +  "description": "Optional. When true, prefix matches the path regardless of case. Prefix only; for a case-insensitive regex start it with (?i).",
      +  "type": "boolean"
      +}
  2. Changed45 schema fields changed
    • removedInput schema / $schema
      Removed value: -"http://json-schema.org/draft-07/schema#"
    • removedInput schema / additionalProperties
      Removed value: -false
    • removedInput schema / properties / description / maxLength
      Removed value: -250
    • changedInput schema / properties / dnsMode / description
      Previous value: -"DNS delegation mode. cname — REQUIRED for apex domains (example.com) and the common choice for a single subdomain. ns — subdomains ONLY (delegates that subdomain zone to Control Plane); the platform rejects ns on an apex."New value: +"DNS delegation mode; derived (cname) with workload. cname works for an apex (example.com) and subdomains; ns delegates a subdomain zone to Control Plane and is rejected on an apex."
    • removedInput schema / properties / domain / maxLength
      Removed value: -253
    • removedInput schema / properties / domain / minLength
      Removed value: -1
    • addedInput schema / properties / gvc
      Added value: +{
      +  "description": "The workload's GVC.",
      +  "type": "string"
      +}
    • changedInput schema / properties / org / description
      Previous value: -"Organization slug (lowercase kebab-case). NEVER guess — if the user has not named one, ask. On org-not-found, stop and ask; do not retry variants."New value: +"Organization slug."
    • removedInput schema / properties / org / maxLength
      Removed value: -63
    • removedInput schema / properties / org / minLength
      Removed value: -1
    • removedInput schema / properties / org / pattern
      Removed value: -"^[a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?$"
    • changedInput schema / properties / ports / description
      Previous value: -"Required listener list. Each listener minimally needs number and protocol; cors, routes, and tls are optional nested blocks."New value: +"Listener list; derived with workload, required otherwise. Each listener needs number and protocol; cors, routes, and tls are optional."
    • removedInput schema / properties / ports / items / additionalProperties
      Removed value: -false
    • removedInput schema / properties / ports / items / properties / cors / additionalProperties
      Removed value: -false
    • removedInput schema / properties / ports / items / properties / cors / properties / allowOrigins / items / additionalProperties
      Removed value: -false
    • removedInput schema / properties / ports / items / properties / cors / properties / maxAge / pattern
      Removed value: -"^[\\d\\.]+[hms]+$"
    • removedInput schema / properties / ports / items / properties / routes / items / additionalProperties
      Removed value: -false
    • removedInput schema / properties / ports / items / properties / routes / items / properties / headers / additionalProperties
      Removed value: -false
    • removedInput schema / properties / ports / items / properties / routes / items / properties / headers / properties / request / additionalProperties
      Removed value: -false
    • removedInput schema / properties / ports / items / properties / routes / items / properties / hostPrefix / pattern
      Removed value: -"^[0-9a-zA-Z-\\._]*$"
    • removedInput schema / properties / ports / items / properties / routes / items / properties / prefix / pattern
      Removed value: -"^\\/[0-9a-zA-Z-\\._~\\/]*$"
    • removedInput schema / properties / ports / items / properties / routes / items / properties / replacePrefix / pattern
      Removed value: -"^\\/[0-9a-zA-Z-\\._~\\/]*$"
    • removedInput schema / properties / ports / items / properties / routes / items / properties / workloadLink / minLength
      Removed value: -1
    • removedInput schema / properties / ports / items / properties / routes / maxItems
      Removed value: -200
    • removedInput schema / properties / ports / items / properties / tls / additionalProperties
      Removed value: -false
    • removedInput schema / properties / ports / items / properties / tls / properties / clientCertificate / additionalProperties
      Removed value: -false
    • removedInput schema / properties / ports / items / properties / tls / properties / clientCertificate / properties / secretLink / minLength
      Removed value: -1
    • removedInput schema / properties / ports / items / properties / tls / properties / serverCertificate / additionalProperties
      Removed value: -false
    • removedInput schema / properties / ports / items / properties / tls / properties / serverCertificate / properties / secretLink / minLength
      Removed value: -1
    • removedInput schema / properties / ports / maxItems
      Removed value: -10
    • removedInput schema / properties / ports / minItems
      Removed value: -1
    • addedInput schema / properties / prefix
      Added value: +{
      +  "description": "Path prefix the derived route matches (default \"/\"). With workload only.",
      +  "type": "string"
      +}
    • removedInput schema / properties / tags / items / additionalProperties
      Removed value: -false
    • removedInput schema / properties / tags / items / properties / key / minLength
      Removed value: -1
    • removedInput schema / properties / tags / maxItems
      Removed value: -50
    • addedInput schema / properties / waitSeconds
      Added value: +{
      +  "description": "Seconds to wait on the server until the domain is ready, 0 to 45. The call returns as soon as it is, or with the latest state when the time runs out. Use this instead of calling again and again.",
      +  "maximum": 45,
      +  "minimum": 0,
      +  "type": "integer"
      +}
    • addedInput schema / properties / workload
      Added value: +{
      +  "description": "Route the domain to this workload (with gvc): the 443 listener, its route, and dnsMode cname are derived.",
      +  "type": "string"
      +}
    • changedInput schema / required
      Previous value: -[
      -  "org",
      -  "domain",
      -  "dnsMode",
      -  "ports"
      -]New value: +[
      +  "domain"
      +]
    • removedOutput schema / $schema
      Removed value: -"http://json-schema.org/draft-07/schema#"
    • removedOutput schema / additionalProperties
      Removed value: -false
    • changedOutput schema / properties / data / description
      Previous value: -"The full machine-readable result — list rows, the resource object, query results. Read THIS, not just the summary."New value: +"The full result. Read this, not only the summary."
    • addedOutput schema / properties / details
      Added value: +{
      +  "type": "string"
      +}
    • removedOutput schema / properties / nextSteps / description
      Removed value: -"Recommended follow-up actions for this task, in order."
    • removedOutput schema / properties / ok / description
      Removed value: -"Whether the call succeeded."
    • removedOutput schema / properties / summary / description
      Removed value: -"One-line summary of the result."
  3. First observed

TDQS

A4.3/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare this is a non-destructive mutation on an open world; the description adds real context beyond that — derived 443 listener/route/cname mode, that the response lists DNS records the user must add, idempotent route-add on an existing domain, and the 45s wait semantics. It does not mention permissions/auth requirements, but the added behavioral detail is substantial.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loads the common case (domain+workload+gvc and what it derives) before the custom path, so the agent gets the default behavior first. Dense but each sentence carries distinct information; slightly long but justified for a 15-parameter tool.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return-value explanation is optional, yet the description still notes the result lists DNS records to add. Combined with the simple/custom split, waitSeconds behavior, and idempotency note, it is nearly complete; it leaves niche options (ns delegation, tags, certChallengeType) to the schema, which is reasonable.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% (baseline 3), but the description goes further by explaining how parameters interact: minimal call is domain+workload+gvc, port items are {number, protocol}, a route needs workloadLink and matches / without prefix. This derivation logic is not obvious from the raw schema and helps the agent assemble a valid call.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Names the specific verb+resource (put/create a domain in front of a workload) and clearly splits the two invocation modes: the derived simple path (domain+workload+gvc) versus the custom path (dnsMode+ports). It also implicitly separates itself from sibling modifiers like add_domain_port/add_domain_route by describing creation of the whole domain rather than a sub-component.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly says which parameter combination selects the simple derived path versus the custom setup path, and notes idempotency ('an existing domain gets the route added') and waitSeconds polling. It does not name sibling alternatives (add_domain_port, add_domain_route, update_domain) that an agent might otherwise pick, so it stops short of full routing guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.