End of development notice: AWS is discontinuing development of Research and Engineering Studio on AWS (RES). 2026.09 is the final release, supported through September 30, 2027. RES remains open source and keeps running in your account. For more information, see RES end of support.
Set up custom domains after RES installation
Note
Prerequisites: You must store Certificate and PrivateKey contents in a Secrets Manager secret before performing these steps.
Add certs to the web client
-
Update the cert attached to the listener of the external-alb load balancer:
-
Navigate to the RES external load balancer in the AWS console under EC2 > Load Balancing > Load Balancers.
-
Search for the load balancer that follows the naming convention
.<env-name>-external-alb -
Check the listeners attached to the load balancer.
-
Update the listener that has a Default SSL/TLS certificate attached with the new certificate details.
-
Save your changes.
-
-
In the cluster-settings table:
-
Find the cluster-settings table in DynamoDB -> Tables ->
.<env-name>.cluster-settings -
Go to Explore Items and Filter by Attribute – name "key", Type "string", condition "contains", and value "external_alb".
-
Set
cluster.load_balancers.external_alb.certificates.providedto True. -
Update the value of
cluster.load_balancers.external_alb.certificates.custom_dns_name. This is the custom domain name for web user interface. -
Update the value of
cluster.load_balancers.external_alb.certificates.acm_certificate_arn. This is the Amazon Resource Name (ARN) for the corresponding certificate stored in Amazon Certificate Manager (ACM).
-
-
Update the corresponding Route53 subdomain record you created for your web client to point to the DNS name of the external alb load balancer
<env-name>-external-alb. -
If SSO is already configured in the environment, re-configure SSO with the same inputs as you used initially from the Environment Management > Identity management > Single Sign-On > Status > Edit button in the RES web portal.
Add certs to the VDIs or rotate certs
-
Grant the RES application permission to perform a GetSecret operation on the secret by adding the following tags to the secrets:
-
res:EnvironmentName:<env-name> -
res:ModuleName:virtual-desktop-controller
-
-
In the cluster-settings table:
-
Find the cluster-settings table in DynamoDB -> Tables ->
.<env-name>.cluster-settings -
Go to Explore Items and Filter by Attribute – name "key", Type "string", condition "contains", and value "dcv_connection_gateway".
-
Set
vdc.dcv_connection_gateway.certificate.providedto True. -
Update the value of
vdc.dcv_connection_gateway.certificate.custom_dns_name. This is the custom domain name for VDI access. -
Update the value of
vdc.dcv_connection_gateway.certificate.certificate_secret_arn. This is the ARN for the secret that holds the Certificate contents. -
Update the value of
vdc.dcv_connection_gateway.certificate.private_key_secret_arn. This is the ARN for the secret that holds the Private Key contents.
-
-
Update the launch template used for the gateway instance:
-
Open the Auto Scaling group in the AWS Console under EC2 > Auto Scaling > Auto Scaling Groups.
-
Select the gateway auto scaling group that corresponds to the RES environment. The name follows the naming convention
.<env-name>-vdc-gateway-asg -
Find and open the Launch Template in the details section.
-
Under Details > Actions > choose Modify template (Create new version).
-
Scroll down to Advanced details.
-
Scroll to the very bottom, to User data.
-
Look for the words
CERTIFICATE_SECRET_ARNandPRIVATE_KEY_SECRET_ARN. Update these values with the ARNs given to the secrets that hold the Certificate (see step 2.c) and Private Key (see step 2.d) contents. -
Ensure the Auto Scaling group is configured to use the recently created version of the launch template (from the Auto Scaling group page).
-
-
Update the corresponding Route53 subdomain record you created for your virtual desktops to point to the DNS name of the external nlb load balancer:
.<env-name>-external-nlb -
Terminate the existing dcv-gateway instance:
and wait for a new one to spin up. The dcv-gateway instance checks daily at 12:00 AM (midnight) UTC for changes to the certificate and private key values stored in Secrets Manager, and automatically retrieves and applies new values if updated.<env-name>-vdc-gateway