# Service Configuration (/docs/guides/service-configuration)



Service configuration controls how your application builds, starts, and runs. Open any service and go to **Deployments** → **Build settings**.

## Build Settings [#build-settings]

* **Dockerfile path** - Set the path if your Dockerfile is not in the repository root (e.g., `backend/Dockerfile`).
* **Build context** - By default, the repository root is used as the build context. If your Dockerfile is in a subdirectory and uses relative paths (e.g., `COPY . .&#x60;), enable &#x2A;*"Use Dockerfile directory as build context"** to use the Dockerfile's directory instead.
* **Dependency vulnerability scan** - Optionally scan every `package-lock.json`, `pnpm-lock.yaml`, `yarn.lock`, and `bun.lock` in the build context before building the image. At least one supported lockfile is required when enabled. Critical library vulnerabilities or scanner errors fail the build and block deployment. Open the deployment's **Vulnerabilities** tab to see scan progress, the passed summary, or findings by CVE and package. Agents read the latest stable build's results with the `list_vulnerabilities` [MCP tool](/docs/guides/mcp-integration).
* **Public access** - Enabled by default. Turn this off to disable the platform URL, custom-domain routes, and preview routes for the service.

See [Dockerfile Requirements](/docs/dockerfile-requirements) for examples of both approaches.

### Public Access [#public-access]

Saving only a **Public access** change updates existing routes without starting a new build or deployment. The running application version stays the same.

Disabling **Public access** removes public routes after existing routes are re-rendered. New previews still build and run, but without public routes. The dashboard, GitHub, and deployment notifications do not link to the disabled URL. Internal service-to-service connectivity continues to work.

Your target URL, basic-auth settings, and custom-domain configuration are preserved. Uptime monitoring pauses while public access is disabled and resumes when you enable it again. While public access is off you cannot add or verify a custom domain, and you cannot configure uptime monitoring, because neither has a public route to check.

## Runtime Settings [#runtime-settings]

* **Target URL** - The first part of the URL is yours to edit. Changing it moves the service to the new URL and the old one stops working - see [Moving an existing app to a new name](#moving-an-existing-app-to-a-new-name). To use your own domain instead, see [Custom Domains](/docs/guides/custom-domains).
* **Port** - The container port your app listens on. Must match your Dockerfile's `EXPOSE` directive.
* **Environment variables** - Key/value pairs and linked secrets, on the **Env Vars** tab. See [Environment Variables](/docs/guides/environment-variables).

## Moving an existing app to a new name [#moving-an-existing-app-to-a-new-name]

Apps created before flat addresses shipped are still on `<service>-<org-slug>.apps.rock8.cloud`. In **Build settings**, edit the Target URL to move to `<name>.rock8cloud.app`.

Moving is instant and the old address stops working right away. Update any env vars that reference it by hand - `BETTER_AUTH_URL`, `CORS_ORIGIN`, `PUBLIC_URL`, and OAuth callback URLs are the common ones.

## Resources [#resources]

The **Resources** tab (next to Build settings) holds everything that draws from your plan's resource pool. Changes apply to the running pods right away, no rebuild:

* **Replicas** - How many copies of the service run behind the same URL. The maximum comes from your plan. Each replica consumes the service's allocation.
* **CPU and memory** - Resize the per-replica allocation in 0.25 vCPU / 256 MiB steps. The plan pool meters show what is still available, with a shortcut to buy more.
* **Resource usage** - Live CPU and memory graphs of the active deployment.

See [Plans & Usage](/docs/plans-and-usage) for pool sizes and add-ons.

## Password Protection (Basic Auth) [#password-protection-basic-auth]

Put a service behind an HTTP basic auth login. Available on the **Earth** plan and above.

1. Open the service and go to **Deployments** → **Build settings**.
2. Enable &#x2A;*Password protect (HTTP basic auth)**.
3. Enter a **Username** and **Password**.
4. Save and redeploy - the credentials apply once the new deployment is live.

Anyone visiting the service is prompted for the username and password before the app loads. To change the password later, enter a new one. Leaving the password field blank keeps the current password. To remove protection, disable the checkbox and redeploy.

## Custom Domains [#custom-domains]

Use your own domain for any service. See [Custom Domains](/docs/guides/custom-domains) for setup instructions.

## Uptime Monitoring [#uptime-monitoring]

Repository services can register uptime monitoring from the **Main** environment overview. Select the platform domain or a verified custom domain, then choose a path such as `/health`. The Uptime card shows current availability, 30-day uptime, average response time, daily incident history, and the last check time.

Pending and failed custom domains remain visible but cannot be selected. Removing the selected custom domain also removes its uptime monitor.

## Troubleshooting [#troubleshooting]

| Problem                 | Solution                                                                  |
| ----------------------- | ------------------------------------------------------------------------- |
| Build fails             | Verify Dockerfile path and build context                                  |
| Service unreachable     | Check that the port matches your app                                      |
| Uptime data unavailable | Confirm the monitored URL and path are reachable from the public internet |
| Config not applied      | Confirm the latest deployment used the new settings                       |

## Related [#related]

* [Custom Domains](/docs/guides/custom-domains)
* [Dockerfile Requirements](/docs/dockerfile-requirements)
* [Environment Variables](/docs/guides/environment-variables)
* [How Rock8Cloud Works](/docs/how-deployments-work)
