fix(gcp): give every data center its own DNS records - #628
Merged
Merged
Conversation
NJona
force-pushed
the
multi-dc-06-per-datacenter-dns
branch
from
August 4, 2026 08:12
875fe8d to
80ef9f8
Compare
NJona
force-pushed
the
multi-dc-06-per-datacenter-dns
branch
from
August 5, 2026 15:48
80ef9f8 to
d1de6c9
Compare
NJona
force-pushed
the
multi-dc-06-per-datacenter-dns
branch
from
August 7, 2026 16:03
d1de6c9 to
ab1e4fe
Compare
NJona
force-pushed
the
multi-dc-06-per-datacenter-dns
branch
from
August 10, 2026 14:17
ab1e4fe to
9d2936f
Compare
NJona
force-pushed
the
multi-dc-06-per-datacenter-dns
branch
2 times, most recently
from
August 12, 2026 09:16
40d9c77 to
1aac951
Compare
NJona
force-pushed
the
multi-dc-06-per-datacenter-dns
branch
from
August 13, 2026 12:48
1aac951 to
5293739
Compare
NJona
force-pushed
the
multi-dc-06-per-datacenter-dns
branch
from
August 14, 2026 07:01
2afb857 to
14f63ad
Compare
NJona
force-pushed
the
multi-dc-06-per-datacenter-dns
branch
from
August 14, 2026 07:15
14f63ad to
e2987cf
Compare
NJona
force-pushed
the
multi-dc-06-per-datacenter-dns
branch
2 times, most recently
from
September 11, 2026 06:32
4923161 to
02b546a
Compare
joka134
reviewed
Sep 14, 2026
NJona
added a commit
that referenced
this pull request
Sep 16, 2026
…ript Review feedback on #628: the DNS record helpers, EnsureDNSRecords, ensureDnsPermissions and dnsARecord now live in their own file in the gcp package, with the standalone DataCenterDNSRecordNames test next to them. push-multi-dc-stack.sh is a local helper that was committed by accident. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
NJona
added a commit
that referenced
this pull request
Sep 16, 2026
…ript Review feedback on #628: the DNS record helpers, EnsureDNSRecords, ensureDnsPermissions and dnsARecord now live in their own file in the gcp package, with the standalone DataCenterDNSRecordNames test next to them. push-multi-dc-stack.sh is a local helper that was committed by accident. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: Jona Neef <Jona.Neef.97@gmail.com>
NJona
force-pushed
the
multi-dc-06-per-datacenter-dns
branch
from
September 16, 2026 13:52
b2709cb to
fba8a82
Compare
NJona
added a commit
that referenced
this pull request
Sep 16, 2026
…ript Review feedback on #628: the DNS record helpers, EnsureDNSRecords, ensureDnsPermissions and dnsARecord now live in their own file in the gcp package, with the standalone DataCenterDNSRecordNames test next to them. push-multi-dc-stack.sh is a local helper that was committed by accident. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: Jona Neef <Jona.Neef.97@gmail.com>
NJona
force-pushed
the
multi-dc-06-per-datacenter-dns
branch
from
September 16, 2026 14:20
fba8a82 to
ba34fa8
Compare
Workspaces resolve per data center, and so does the platform: the frontend asks <dc-id>.<codesphere.domain> for the configuration of the data center a workspace lives in. OMS only created cs.<base-domain> and its wildcard, both pointing at the first data center's gateway, so with more than one data center the second one's endpoint resolved to the first's gateway, which has no route for that host — every browser request for it was reset, and since the frontend fetches that config before rendering, the whole UI failed. EnsureDNSRecords now creates, per data center, its workspace hosting names and SSH proxy name pointing at its own public gateway and SSH proxy, plus <dc-id>.cs.<base-domain> and its wildcard pointing at its own platform gateway. The per-data-center platform names are only created when there is more than one data center: a single one is the primary, which cs.<base-domain> already resolves to. The records that were created are recorded in the infra file, so cleanup deletes exactly those. DeleteDNSRecordSets therefore takes the record list instead of a base domain, and cleanup falls back to deriving the names for infra files written before this and for a cleanup driven only by --project-id. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Signed-off-by: Jona Neef <Jona.Neef.97@gmail.com>
Signed-off-by: NJona <25478046+NJona@users.noreply.github.com>
…ript Review feedback on #628: the DNS record helpers, EnsureDNSRecords, ensureDnsPermissions and dnsARecord now live in their own file in the gcp package, with the standalone DataCenterDNSRecordNames test next to them. push-multi-dc-stack.sh is a local helper that was committed by accident. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: Jona Neef <Jona.Neef.97@gmail.com>
Rename ensureDnsPermissions to ensureDNSPermissions and document EnsureDNSRecords; moving them into dns.go put them in the linter's changed-files scope. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: Jona Neef <Jona.Neef.97@gmail.com>
NJona
force-pushed
the
multi-dc-06-per-datacenter-dns
branch
from
September 22, 2026 06:18
ba34fa8 to
14a9013
Compare
Signed-off-by: NJona <25478046+NJona@users.noreply.github.com>
DerBurri
pushed a commit
that referenced
this pull request
Sep 23, 2026
Workspaces resolve per data center, and so does the platform: the frontend asks `<dc-id>.<codesphere.domain>` for the configuration of the data center a workspace lives in. OMS only created `cs.<base-domain>` and its wildcard, both pointing at the first data center's gateway, so with more than one data center the second one's endpoint resolved to the first's gateway, which has no route for that host. Every browser request for it was reset — and since the frontend fetches that config before rendering anything, the whole UI failed. `EnsureDNSRecords` now creates, per data center, its workspace hosting names and SSH proxy name pointing at its own public gateway and SSH proxy, plus `<dc-id>.cs.<base-domain>` and its wildcard pointing at its own **platform** gateway. ## Review notes - The per-data-center platform names are only created when there is more than one data center: a single one *is* the primary, which `cs.<base-domain>` already resolves to. So single-DC bootstraps still create exactly the same five records. - The created records are recorded in the infra file so cleanup deletes exactly those. `DeleteDNSRecordSets` therefore takes the record list instead of a base domain; cleanup falls back to deriving the names for older infra files and for a cleanup driven only by `--project-id`. - Verified against a live two-data-center instance: adding these two records was what made the second data center reachable. --- Part of the `oms beta bootstrap-gcp --multi-dc` stack (10 PRs). Merge in order; each PR is based on its predecessor. --------- Signed-off-by: Jona Neef <Jona.Neef.97@gmail.com> Signed-off-by: NJona <25478046+NJona@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Workspaces resolve per data center, and so does the platform: the frontend asks
<dc-id>.<codesphere.domain>for the configuration of the data center a workspace lives in. OMS only createdcs.<base-domain>and its wildcard, both pointing at the first data center's gateway, so with more than one data center the second one's endpoint resolved to the first's gateway, which has no route for that host. Every browser request for it was reset — and since the frontend fetches that config before rendering anything, the whole UI failed.EnsureDNSRecordsnow creates, per data center, its workspace hosting names and SSH proxy name pointing at its own public gateway and SSH proxy, plus<dc-id>.cs.<base-domain>and its wildcard pointing at its own platform gateway.Review notes
cs.<base-domain>already resolves to. So single-DC bootstraps still create exactly the same five records.DeleteDNSRecordSetstherefore takes the record list instead of a base domain; cleanup falls back to deriving the names for older infra files and for a cleanup driven only by--project-id.Part of the
oms beta bootstrap-gcp --multi-dcstack (10 PRs). Merge in order; each PR is based on its predecessor.