Drop the demo.lumbridgecorp.com alias; one hostname
The site is demo.primeintellectgrowth.com and nothing else. The Caddy block, the deploy smoke test, the mirrored Caddyfile and the docs all carried the second name; all four no longer do.
This commit is contained in:
@@ -128,9 +128,6 @@ scores above zero.
|
|||||||
|
|
||||||
Full accounting: [demo.primeintellectgrowth.com/honesty](https://demo.primeintellectgrowth.com/honesty)
|
Full accounting: [demo.primeintellectgrowth.com/honesty](https://demo.primeintellectgrowth.com/honesty)
|
||||||
|
|
||||||
Also served at [demo.lumbridgecorp.com](https://demo.lumbridgecorp.com); the
|
|
||||||
canonical name is the first one and every page says so in its `<link rel=canonical>`.
|
|
||||||
|
|
||||||
## Adding a demo
|
## Adding a demo
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
|
|||||||
@@ -1,10 +1,7 @@
|
|||||||
# The live block on cloud-2, kept here so the config is reviewable in the repo.
|
# The live block on cloud-2, kept here so the config is reviewable in the repo.
|
||||||
# Copy of /etc/caddy/Caddyfile's demo section — if you change one, change both.
|
# Copy of /etc/caddy/Caddyfile's demo section — if you change one, change both.
|
||||||
|
|
||||||
# Both names serve the same build from the same root. The prerendered HTML
|
demo.primeintellectgrowth.com {
|
||||||
# carries <link rel=canonical> pointing at the primeintellectgrowth name, so
|
|
||||||
# the second hostname does not split search ranking between two copies.
|
|
||||||
demo.primeintellectgrowth.com, demo.lumbridgecorp.com {
|
|
||||||
# REQUIRED, and its absence is silent. Without it Caddy builds a second
|
# REQUIRED, and its absence is silent. Without it Caddy builds a second
|
||||||
# server on *:443 that has never heard of this hostname, and public traffic
|
# server on *:443 that has never heard of this hostname, and public traffic
|
||||||
# — which NATs to 10.0.0.2 — falls through to an empty 200 behind a
|
# — which NATs to 10.0.0.2 — falls through to an empty 200 behind a
|
||||||
|
|||||||
+3
-20
@@ -10,30 +10,13 @@ pnpm build && bash deploy/deploy.sh
|
|||||||
|
|
||||||
| | |
|
| | |
|
||||||
|---|---|
|
|---|---|
|
||||||
| Hostnames | `demo.primeintellectgrowth.com` (canonical) and `demo.lumbridgecorp.com` (alias) |
|
| Hostname | `demo.primeintellectgrowth.com` — the only one |
|
||||||
| Host | cloud-2, `ubuntu@100.92.185.76` (tailnet only) |
|
| Host | cloud-2, `ubuntu@100.92.185.76` (tailnet only) |
|
||||||
| Root | `/var/www/demo.primeintellectgrowth.com` |
|
| Root | `/var/www/demo.primeintellectgrowth.com` |
|
||||||
| Snapshots | `…-rollbacks/`, last 10, hard-linked |
|
| Snapshots | `…-rollbacks/`, last 10, hard-linked |
|
||||||
| DNS | OCI zone `primeintellectgrowth.com` → `170.9.14.61`, explicit A record, no wildcard. The alias needs no record: `lumbridgecorp.com` has a wildcard |
|
| DNS | OCI zone `primeintellectgrowth.com` → `170.9.14.61`, explicit A record, no wildcard |
|
||||||
| Caddy | one block for both names, mirrored in `Caddyfile.demo` |
|
| Caddy | one block, mirrored in `Caddyfile.demo` |
|
||||||
|
|
||||||
## Two hostnames, one root
|
|
||||||
|
|
||||||
Both names serve the same build. The prerendered HTML carries
|
|
||||||
`<link rel="canonical">` and `og:url` pointing at the **primeintellectgrowth**
|
|
||||||
name on every route, so the alias does not split search ranking or make a shared
|
|
||||||
link ambiguous about which site it belongs to.
|
|
||||||
|
|
||||||
⚠️ **`lumbridgecorp.com` resolves on a wildcard.** Every subdomain of it points
|
|
||||||
at cloud-2 whether or not Caddy has a block for it — so an unconfigured or
|
|
||||||
mistyped name completes DNS, opens TLS, finds no certificate for that SNI, and
|
|
||||||
fails the handshake with `ERR_SSL_PROTOCOL_ERROR`. That reads as "the site is
|
|
||||||
broken" when it means "that is not a site". `primeintellectgrowth.com` has no
|
|
||||||
wildcard, which is why the canonical name needed an explicit A record.
|
|
||||||
|
|
||||||
`deploy.sh` smoke-tests the alias for exactly this reason: if the block is ever
|
|
||||||
edited to drop the second name, the failure is a TLS error rather than a 404,
|
|
||||||
and nothing else would notice.
|
|
||||||
|
|
||||||
## The trap that costs an afternoon
|
## The trap that costs an afternoon
|
||||||
|
|
||||||
|
|||||||
@@ -14,11 +14,6 @@ HOST="${PIG_DEMO_HOST:-ubuntu@100.92.185.76}"
|
|||||||
ROOT="/var/www/demo.primeintellectgrowth.com"
|
ROOT="/var/www/demo.primeintellectgrowth.com"
|
||||||
SNAPS="${ROOT}-rollbacks"
|
SNAPS="${ROOT}-rollbacks"
|
||||||
URL="https://demo.primeintellectgrowth.com"
|
URL="https://demo.primeintellectgrowth.com"
|
||||||
# Served from the same root under a second name. Checked because DNS for
|
|
||||||
# lumbridgecorp.com is a WILDCARD: the alias resolves whether or not Caddy knows
|
|
||||||
# about it, and an unconfigured name fails the TLS handshake outright rather
|
|
||||||
# than 404ing — which reads as "the site is down", not "wrong hostname".
|
|
||||||
ALIAS="https://demo.lumbridgecorp.com"
|
|
||||||
|
|
||||||
cd "$(dirname "$0")/.."
|
cd "$(dirname "$0")/.."
|
||||||
|
|
||||||
@@ -74,8 +69,5 @@ for path in /sitemap.xml /robots.txt /og/wordle.png; do
|
|||||||
[ "$code" = "200" ] || { echo "FAILED: $path returned $code"; exit 1; }
|
[ "$code" = "200" ] || { echo "FAILED: $path returned $code"; exit 1; }
|
||||||
done
|
done
|
||||||
|
|
||||||
alias_code=$(curl -sS -o /dev/null -w '%{http_code}' --max-time 30 "$ALIAS/" || echo 000)
|
|
||||||
echo " alias $ALIAS -> $alias_code"
|
|
||||||
[ "$alias_code" = "200" ] || { echo "FAILED: the alias hostname returned $alias_code"; exit 1; }
|
|
||||||
|
|
||||||
echo "==> live: $URL"
|
echo "==> live: $URL"
|
||||||
|
|||||||
Reference in New Issue
Block a user