Skip to content

Document preview hosts and custom domain name rules on Fabric - #718

Open
dawsontoth wants to merge 11 commits into
mainfrom
docs/fabric-wildcard-custom-domains
Open

dawsontoth wants to merge 11 commits into
mainfrom
docs/fabric-wildcard-custom-domains

Conversation

@dawsontoth

@dawsontoth dawsontoth commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Documents two Fabric changes that HarperFast/central-manager#917 makes, with HarperFast/host-manager#244:

  • Preview hosts: every cluster serves isolated applications under app. and its own host name, pr-42.app.<cluster name>.<organization subdomain>.harperfabric.com. There is no setting.
  • Custom domain name rules: names are case-insensitive and stored in lowercase, must be valid hostnames, cannot be a cluster's host name or a name under it, and belong to one organization once verified.

Depends-on: #715

Merge order

  1. Document isolated applications, branched databases, and per-PR CI previews #715, which adds the isolated-applications section this page links to.
  2. HarperFast/central-manager#917, which carries the merged HarperFast/central-manager#887, then HarperFast/host-manager#244, deployed.
  3. This PR, once those are live, so the page does not describe preview hosts before they work.

For the human reviewer

  1. Preview hosts moved under app. Let's Encrypt refuses the wildcard of a cluster's host name beside the instance names one label under it, as review of host-manager#244 found and Let's Encrypt staging confirmed, so previews are pr-42.app.<cluster name>.…; app was your call. The page no longer warns against naming a preview after an instance, since the two no longer overlap.
  2. The design changed under this PR. Preview hosts were a per-cluster namespace keyed on the cluster ID and turned on through the Fabric API. At your call they moved to a wildcard under each cluster's own host name, on every cluster, with no setting, so the API instructions, the cluster ID and the open question about API authentication are gone.
  3. When previews work on an existing cluster. The page says a cluster created earlier gains them one instance at a time, within about seven weeks, and that until then previews on a multi-instance cluster are intermittent, since a request that lands on an instance without the new certificate fails TLS. That is the cost of adding the wildcard at each certificate's normal renewal rather than re-issuing the fleet at once. From February 2027 Let's Encrypt's shorter certificates shorten the window; the page would then say so.
  4. The same-site boundary is documented, not enforced (decision 7 in central-manager#917). The page tells customers to preview only code they would trust in production, recommends __Host- names (with Secure, Path=/ and no Domain) for cookies production relies on, says Harper's own session cookie cannot take that prefix because its name is fixed (hdb-session), and that SameSite does not separate a preview from production.

Changes

Verification

  • Docs-only. npx prettier --check is clean on both files.
  • Each statement was checked against the companion code:
    • the host name shape and the one-label rule match central-manager's *.app.<cluster> record and host-manager's wildcard application routing, which covers one label;
    • "only isolated applications" and "no response" match host-manager never routing the wildcard to the shared workers;
    • the instance host names, central-manager's <location>-<n>.<cluster host name>, sit outside app., so no preview host can be one;
    • the renewal timing matches host-manager's 40-day renewal threshold on 90-day certificates;
    • Harper's session cookie name is fixed: security/auth.ts builds it as [origin-]hdb-session;
    • the custom domain rules match customDomains.js and clusterHostNames.
  • Nothing here is observable end to end until #917 and Fix Open Graph images to render well across all social media sites #244 deploy; the deployed canary in #917's rollout covers it.

Related PRs: none found
Complexity: easy

🤖 Generated with Claude Code

Review-Coverage: authored=claude; ran=gemini,cursor-composer,codex; adjudicated=domain; declined=cursor-grok,cursor-kimi,cursor-muse; rounds=5; full=1 @ 62dff49

Review-Attention: skim ~2m (decisions: previews-same-site-as-production, always-on-previews, renewal-driven-rollout, fabric-owned-preview-hosts) @ 62dff49

dawsontoth and others added 2 commits October 7, 2026 14:53
A Fabric custom domain can be a wildcard such as *.preview.example.com, covering one label
below its base, so per-PR preview hosts need one registration instead of one each. The page
now covers where its TXT record goes (_fabric.<base>), its CNAME, that a more specific domain
wins, and that its certificate is the customer's: Fabric's automatic certificates use
Let's Encrypt's HTTP-01 challenge, and Let's Encrypt issues wildcards only through DNS-01. The
certificate is added with add_certificate against the cluster's Operations API. Also notes that
domain names are case-insensitive and claimable by one organization once verified.

Companion to HarperFast/central-manager#917 and HarperFast/host-manager#244; merge after both
ship.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…s API URL, replication

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
gemini-code-assist[bot]

This comment was marked as outdated.

@github-actions
github-actions Bot temporarily deployed to pr-718 October 7, 2026 19:12 Inactive
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

🚀 Preview Deployment

Your preview deployment is ready!

🔗 Preview URL: https://preview.harper-documentation.harperfabric.com/pr-718

This preview will update automatically when you push new commits.

Customer wildcard custom domains were dropped from HarperFast/central-manager#917. The page
keeps the rules that still hold: names are case-insensitive and stored lowercase, must be valid
hostnames, and belong to one organization once verified.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@dawsontoth dawsontoth changed the title Document wildcard custom domains on Fabric Document custom domain name rules on Fabric Oct 7, 2026
@github-actions
github-actions Bot temporarily deployed to pr-718 October 7, 2026 19:24 Inactive
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

🚀 Preview Deployment

Your preview deployment is ready!

🔗 Preview URL: https://preview.harper-documentation.harperfabric.com/pr-718

This preview will update automatically when you push new commits.

dawsontoth and others added 3 commits October 7, 2026 16:07
A cluster can now serve isolated applications under *.preview.<cluster hostname>
(HarperFast/central-manager#917, HarperFast/host-manager#244): Fabric creates the
DNS record and orders the wildcard on each instance's certificate, so a preview
needs only a deploy. Documents what reaches a preview host, the one-label rule,
which clusters qualify, and the API request that turns it on until Studio has a
setting.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…osts on

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
HarperFast/central-manager#917 now keys each cluster's preview namespace on
its ID, *.<cluster id>.preview.<organization subdomain>.harperfabric.com,
instead of the cluster's hostname, so the page shows that shape, drops the
default-hostname requirement, and says where the ID is before the URL needs it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@dawsontoth dawsontoth changed the title Document custom domain name rules on Fabric Document preview hosts and custom domain name rules on Fabric Oct 8, 2026
@github-actions
github-actions Bot temporarily deployed to pr-718 October 8, 2026 03:54 Inactive
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

🚀 Preview Deployment

Your preview deployment is ready!

🔗 Preview URL: https://preview.harper-documentation.harperfabric.com/pr-718

This preview will update automatically when you push new commits.

dawsontoth and others added 4 commits October 8, 2026 12:45
Preview hosts move from a per-cluster namespace turned on through the Fabric API to the wildcard of
the cluster's own host name, which every cluster gets: pr-42.<cluster name>.<org>.harperfabric.com.
Documents when existing clusters start serving them, and the cookie boundary between a cluster and
its previews, recommending __Host- cookie names.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A preview runs under the cluster's own host name: recommend previewing only code trusted in
production, give the attributes a __Host- cookie needs, note that Harper's own session cookie cannot
take the prefix and that SameSite does not separate the two, and say that previews on an older
multi-instance cluster are intermittent until every instance's certificate renews.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions
github-actions Bot temporarily deployed to pr-718 October 8, 2026 18:31 Inactive
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

🚀 Preview Deployment

Your preview deployment is ready!

🔗 Preview URL: https://preview.harper-documentation.harperfabric.com/pr-718

This preview will update automatically when you push new commits.

@dawsontoth
dawsontoth marked this pull request as ready for review October 8, 2026 19:51
@dawsontoth
dawsontoth requested a review from a team as a code owner October 8, 2026 19:51
Fabric now serves previews at pr-42.app.<cluster>.<org>.harperfabric.com:
Let's Encrypt will not issue *.<cluster host name> beside the cluster's
instance names, which sit one label under it. A host directly under the
cluster's host name no longer reaches a preview, and the instance names no
longer overlap preview names.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown

🚀 Preview Deployment

Your preview deployment is ready!

🔗 Preview URL: https://preview.harper-documentation.harperfabric.com/pr-718

This preview will update automatically when you push new commits.

This branch was successfully deployed

1 active deployment
pr-718 — 62dff491 Deployed Oct 9, 2026 by github-actions[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant