Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260928-2133-cvedb-io-to-cvedb-dev

rdmsm4x - migration - cvedb.io to cvedb.dev canonical domain move - claude@rdmsm4x - TASK-20260928-29 - cvedb - 2026-09-28 21:33:11 EDT

Span: 2026-09-28 21:20:28 EDT to 2026-09-28 21:33:11 EDT, on rdmsm4x (headless run).

Result: cvedb.dev is now the canonical domain. It serves everything cvedb.io served: the same Access-gated cvedb edge Worker, the cvedb-api backend and D1, with owner-only Google sign-in. cvedb.io and www.cvedb.io return a 301 to https://cvedb.dev, keeping the path and query, and the redirect fires before Access. Nothing was bought, renewed, transferred or cancelled at GoDaddy. No DNS record was deleted.

What cvedb.io actually was (inventory)

Surface cvedb.io (before) cvedb.dev (after)
Zone active, Free, NS anahi/archer active, Free, NS gannon/kinsley (already delegated)
DNS apex + www CNAME cvedb.pages.dev, proxied (2 records) apex + www CNAME cvedb.pages.dev, proxied, added; the 3 parking records (null MX, SPF -all, DMARC reject) kept
Worker routes cvedb.io/*, www.cvedb.io/* → cvedb cvedb.dev/*, www.cvedb.dev/* → cvedb, added (io routes kept)
Access apps cvedb.io, *.cvedb.io (owner-only Google, 24 h) cvedb.dev (d77a0c55…), *.cvedb.dev (68ed582c…), created with an identical policy
Pages cvedb custom domains cvedb.io, www.cvedb.io cvedb.dev, www.cvedb.dev added (status pending validation; not on the serving path, because the Worker route answers first)
TLS Universal SSL Universal SSL, Google Trust Services WE1, SAN cvedb.dev, *.cvedb.dev
Email routing unconfigured unconfigured (nothing to move)
Redirect / page rules none cvedb.io zone: Single Redirect ruleset 4f5b6532…, rule faec83ca… (301)

Code references (grep -rn "cvedb\.io", 2026-09-28):

Scope Count
apps/cvedb 30 files, 70 occurrences
sites/ 274 files, 2,876 lines (mostly generated wiki/dist mirrors in other lanes)
lib/ 1 file, plus lib/domains docs
Live Worker cvedb-api 15 occurrences
Live Worker site.mjs 3 occurrences
Live Worker edge.mjs 2 occurrences

App Store metadata had no cvedb.io references. The cveDB.ios hits were false positives from bundle IDs.

What changed

  1. Backups first (21:23:19):
    • lib/domains/dns-backups/cvedb.{io,dev}-20260928-212319.{bind,json}
    • backup-20260928-212319/ in this folder: routes, rulesets, zone settings, email routing, Access apps, Pages domains, and both Worker scripts and settings. Secret values are not exported.
  2. Workers (bytes verified identical after upload; D1 binding, secrets and both cron schedules preserved; workers.dev URLs stay disabled):
    • cvedb-api: cvedb.io → cvedb.dev in the OpenAPI servers and contact, the docs page, CLI examples, User-Agent, export header and legacy defaults.
    • cvedb edge site.mjs: canonical link, report header and example Origin now use cvedb.dev.
    • cvedb edge edge.mjs:
      • The www → apex redirect is now host-generic.
      • The internal API URL uses cvedb.dev.
      • ACCESS_AUDIENCES gained the cvedb.dev and www.cvedb.dev AUDs. The cvedb.io ones are kept for rollback.
      • JWT aud accepts an RFC 7519 string on exact match. Service-token JWTs carry a string, and the old check silently 403'd them. Access policy still decides who gets a JWT, so this does not widen access.
    • Source: work/new/; pre-change source: work/baseline/; deploy tooling: work/deploy.py, work/redeploy_edge.py.
  3. DNS, routes, Access and Pages domains for cvedb.dev: see the table above.
  4. 301: Single Redirect on the cvedb.io zone. The rule is (http.host eq "cvedb.io") or (http.host eq "www.cvedb.io") → concat("https://cvedb.dev", http.request.uri.path), with the query string preserved.
  5. apps/cvedb: 70 occurrences in 30 files → cvedb.dev, 0 remaining. SESSION-STATE.md has a new entry.

Commits (pushed to fleet and backup)

Repo SHA What
apps/cvedb f2e4017 reference switch + SESSION-STATE
lib/domains f97d826 pre-migration DNS backups (4 files)

Tests

Endpoints verified (live, work/verify.sh)

The authenticated run used a temporary Access service token plus a non-identity policy on the two cvedb.dev apps. Both were deleted afterwards and the revoked token now gets a 302 to the login page.

Authenticated run: 27/27 PASS (work/verification-authenticated.log).

Check Status
cvedb.io and www.cvedb.io: /, /cve/CVE-2024-3094?x=1&y=2, /v1/status?a=b, /nonexistent-xyz (8 checks) 301 → same path+query on https://cvedb.dev
anonymous cvedb.dev/, /v1/status, www.cvedb.dev/ 302 → its own Access login
cvedb.dev/ 200, canonical https://cvedb.dev/, 0 cvedb.io refs, 59,443 B
/v1/status 200, total_cves 398,871
/v1/health 200
/v1/openapi.json 200, servers[0] = https://cvedb.dev
/v1/docs 200, base https://cvedb.dev
/v1/cve/CVE-2024-3094 and /cve/CVE-2024-3094 200
/v1/search 200
POST /v1/match, same origin 200
www.cvedb.dev/cve/…?x=1 302 → https://cvedb.dev/cve/…?x=1
genuine errors: /nonexistent-xyz 404
/v1/ingest 404
/v1/auth/start 404
cross-origin POST /v1/match 403
DELETE / 405
forged JWT header with no Access session 302 (still gated)

After cleanup: 12/12 PASS (work/verification-post-cleanup.log).

Rollback

  1. Delete the redirect rule on the cvedb.io zone. Its Worker routes, Access apps and DNS were never touched.
  2. Re-upload work/baseline/* with work/deploy_lib.py.

The cvedb.dev additions can stay in place or be removed independently.

Left open