rdmsm4x - migration - cvedb.io to cvedb.dev canonical domain move - claude@rdmsm4x - TASK-20260928-29 - cvedb - 2026-09-28 21:33:11 EDT
Span: 2026-09-28 21:20:28 EDT to 2026-09-28 21:33:11 EDT, on rdmsm4x (headless run).
Result: cvedb.dev is now the canonical domain. It
serves everything cvedb.io served: the same Access-gated
cvedb edge Worker, the cvedb-api backend and
D1, with owner-only Google sign-in. cvedb.io and www.cvedb.io return a 301 to https://cvedb.dev, keeping the
path and query, and the redirect fires before Access. Nothing was
bought, renewed, transferred or cancelled at GoDaddy. No DNS record was
deleted.
What cvedb.io actually was (inventory)
| Surface | cvedb.io (before) | cvedb.dev (after) |
|---|---|---|
| Zone | active, Free, NS anahi/archer | active, Free, NS gannon/kinsley (already delegated) |
| DNS | apex + www CNAME cvedb.pages.dev, proxied (2
records) |
apex + www CNAME cvedb.pages.dev, proxied,
added; the 3 parking records (null MX, SPF
-all, DMARC reject) kept |
| Worker routes | cvedb.io/*, www.cvedb.io/* →
cvedb |
cvedb.dev/*, www.cvedb.dev/* →
cvedb, added (io routes kept) |
| Access apps | cvedb.io, *.cvedb.io (owner-only Google,
24 h) |
cvedb.dev (d77a0c55…),
*.cvedb.dev (68ed582c…),
created with an identical policy |
Pages cvedb custom domains |
cvedb.io, www.cvedb.io | cvedb.dev, www.cvedb.dev
added (status pending validation; not on
the serving path, because the Worker route answers first) |
| TLS | Universal SSL | Universal SSL, Google Trust Services WE1, SAN
cvedb.dev, *.cvedb.dev |
| Email routing | unconfigured | unconfigured (nothing to move) |
| Redirect / page rules | none | cvedb.io zone: Single Redirect ruleset 4f5b6532…, rule
faec83ca… (301) |
Code references (grep -rn "cvedb\.io",
2026-09-28):
| Scope | Count |
|---|---|
apps/cvedb |
30 files, 70 occurrences |
sites/ |
274 files, 2,876 lines (mostly generated wiki/dist mirrors in other lanes) |
lib/ |
1 file, plus lib/domains docs |
Live Worker cvedb-api |
15 occurrences |
Live Worker site.mjs |
3 occurrences |
Live Worker edge.mjs |
2 occurrences |
App Store metadata had no cvedb.io references. The
cveDB.ios hits were false positives from bundle IDs.
What changed
- Backups first (21:23:19):
lib/domains/dns-backups/cvedb.{io,dev}-20260928-212319.{bind,json}backup-20260928-212319/in this folder: routes, rulesets, zone settings, email routing, Access apps, Pages domains, and both Worker scripts and settings. Secret values are not exported.
- Workers (bytes verified identical after upload; D1
binding, secrets and both cron schedules preserved; workers.dev URLs
stay disabled):
cvedb-api:cvedb.io→cvedb.devin the OpenAPI servers and contact, the docs page, CLI examples, User-Agent, export header and legacy defaults.cvedbedgesite.mjs: canonical link, report header and example Origin now usecvedb.dev.cvedbedgeedge.mjs:- The www → apex redirect is now host-generic.
- The internal API URL uses
cvedb.dev. ACCESS_AUDIENCESgained the cvedb.dev and www.cvedb.dev AUDs. The cvedb.io ones are kept for rollback.- JWT
audaccepts an RFC 7519 string on exact match. Service-token JWTs carry a string, and the old check silently 403'd them. Access policy still decides who gets a JWT, so this does not widen access.
- Source:
work/new/; pre-change source:work/baseline/; deploy tooling:work/deploy.py,work/redeploy_edge.py.
- DNS, routes, Access and Pages domains for cvedb.dev: see the table above.
- 301: Single Redirect on the cvedb.io zone. The rule
is
(http.host eq "cvedb.io") or (http.host eq "www.cvedb.io")→concat("https://cvedb.dev", http.request.uri.path), with the query string preserved. - apps/cvedb: 70 occurrences in 30 files →
cvedb.dev, 0 remaining. SESSION-STATE.md has a new entry.
Commits (pushed to
fleet and backup)
| Repo | SHA | What |
|---|---|---|
apps/cvedb |
f2e4017 |
reference switch + SESSION-STATE |
lib/domains |
f97d826 |
pre-migration DNS backups (4 files) |
Tests
- Go (
go test -count=1 ./...): 26 packages ok, 0 FAIL, 6 with no test files. 210 top-level tests and 296 subtests PASS, 0 FAIL. - Worker security suite (
node --test):- Baseline live source: 13/13 pass.
- Migrated source: 16/16 pass.
- Negative control: the baseline
edge.mjsfails 4 of the 16, so the new tests do detect the change.
Endpoints verified (live,
work/verify.sh)
The authenticated run used a temporary Access service token plus a non-identity policy on the two cvedb.dev apps. Both were deleted afterwards and the revoked token now gets a 302 to the login page.
Authenticated run: 27/27 PASS
(work/verification-authenticated.log).
| Check | Status |
|---|---|
cvedb.io and www.cvedb.io: /,
/cve/CVE-2024-3094?x=1&y=2,
/v1/status?a=b, /nonexistent-xyz (8
checks) |
301 → same path+query on
https://cvedb.dev |
anonymous cvedb.dev/, /v1/status,
www.cvedb.dev/ |
302 → its own Access login |
cvedb.dev/ |
200, canonical https://cvedb.dev/, 0
cvedb.io refs, 59,443 B |
/v1/status |
200, total_cves 398,871 |
/v1/health |
200 |
/v1/openapi.json |
200, servers[0] =
https://cvedb.dev |
/v1/docs |
200, base https://cvedb.dev |
/v1/cve/CVE-2024-3094 and
/cve/CVE-2024-3094 |
200 |
/v1/search |
200 |
POST /v1/match, same origin |
200 |
www.cvedb.dev/cve/…?x=1 |
302 → https://cvedb.dev/cve/…?x=1 |
genuine errors: /nonexistent-xyz |
404 |
/v1/ingest |
404 |
/v1/auth/start |
404 |
cross-origin POST /v1/match |
403 |
DELETE / |
405 |
| forged JWT header with no Access session | 302 (still gated) |
After cleanup: 12/12 PASS
(work/verification-post-cleanup.log).
Rollback
- Delete the redirect rule on the cvedb.io zone. Its Worker routes, Access apps and DNS were never touched.
- Re-upload
work/baseline/*withwork/deploy_lib.py.
The cvedb.dev additions can stay in place or be removed independently.
Left open
- TASK-20260928-30 (handed to
sites@rdmsm4x, with dev.ecs0.net fordocs@rdmsm4x): site sources still name cvedb.io. The main ones areeastcoastscience.com-v2catalog.json(website),gen_portfolio.py, dataroo.dev docs and the portfolio JSONs, followed by regenerating the wiki and dist mirrors. The 301 covers them meanwhile. Renaming thesites/cvedb.iodesign-archive repo is a controller call. - SEC-20260928-02 (handed to
ops@rdmsm4x): thecvedb-api-keysskill and 3 llm-wiki/Claude-Projects files hold the NVD API key value in plaintext. Rotation is recommended. - Live Worker source is not in any git repo. It lives
only in
_handoff/folders (as it did after 2026-09-10). Suggest the controller give it a home, for examplesites/cvedb.dev. make buildin apps/cvedb fails with "bin/cvedb already exists and is not an object file".bin/cvedbis a universal2 binary from 09-22 thatgo buildrefuses to overwrite. This predates the migration and I left it unchanged./cve/<unknown-id>returns 200 with{"error":"not found"}, because the backend answers 200 for a missing CVE. This predates the migration.- This LAN intercepts DNS on port 53.
dig @kinsley.ns.cloudflare.com www.cvedb.devreturned a cached NXDOMAIN while Cloudflare and Google DoH resolved it correctly.verify.shresolves www over DoH for that reason. - The Pages custom domains for cvedb.dev/www show
pendingvalidation. They are harmless and not on the serving path. - cvedb.io expires 2027-02-19 (auto-renew OFF). The redirect stops working then; nothing to do before that.