feat(traffic): strip platform-managed hostnames from wrangler config on every deploy #482
No reviewers
Labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
gmackie/ForgeGraph!482
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/strip-managed-routes"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Closes the last steal vector, found by auditing the whole fleet rather than one app.
The finding
Of the 22 enabled one-box apps, 18 declare their own one-box hostname in their wrangler config. Only
controlsfoundry,streamconductor,jobs-pulseand (after #479)forgegraphare clean.Agent 0.1.57's route strip fires only when the deploy carries a
--nameoverride, so canary and preview deploys were already safe — but the one-box primary deploy, whose config name legitimately matches the target, slipped through. Every production deploy of those 18 apps re-attached its public hostname from the router to the primary worker: the split was bypassed until the next reconcile sweep, with a brief unattached window during the swap.habit-app,latchflow,veritas,netcontrol,insure,test-dojoandcalzoneare among them.The fix
The control plane sends the split's hostnames as
managedHostnamesin the deploy payload (only forcloudflare-workersdeployments with an enabled split), and the agent removes only the route entries matching them:{ "pattern": "shop.example.com", "custom_domain": true }→ stripped{ "pattern": "api.shop.example.com" }→ kept (not platform-managed)"shop.example.com/*"androute = "..."scalars → matched on the hostname partenvblocks handled; the app'snamenever touchedSo an app can still declare routes of its own; it just can't claim a hostname the router owns. This makes the #458 reconcile a safety net rather than the mechanism that holds routing together.
The alternative was 18 per-repo config PRs, which fixes today's fleet but not the next app onboarded.
Agent tests +
pkg/clientgreen,go vetclean,tscclean on apps/web. Needs an agent release to take effect; until then the reconcile continues to cover it.🤖 Generated with Claude Code
https://claude.ai/code/session_01CMpzX1b6swjezEptw3T71f
An audit of the 22 enabled one-box apps found 18 declaring their own one-box hostname in wrangler config. Agent 0.1.57's strip only fires on a --name override, so canary and preview deploys were safe but the one-box PRIMARY deploy — whose config name legitimately matches the target — kept re-attaching the public hostname to the primary worker. The split was then bypassed until the next reconcile sweep, with a brief unattached window during the swap. The control plane now sends the split's hostnames as managedHostnames in the deploy payload, and the agent removes only the route entries matching them. Routes the platform does not manage are left untouched, so an app can still declare an API subdomain of its own. Matching is on the hostname part of the pattern, so bare, wildcard and {pattern, custom_domain} forms all match. This makes the reconcile a safety net rather than the mechanism. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CMpzX1b6swjezEptw3T71fPreview environment is live: https://pr-482-forgegraph.forgegraf.com
Deployed
52510e25with the beta stage's environment. It redeploys on every push and is destroyed when this PR closes.