Skip to main content

MC #105767 — Bilko Demo CORS/DNS Fix (OCD-11 Resolved)

MC #105767 — Bilko Demo Env CORS/API-host + DNS Retirement (OCD-11 closed)

Date: 2026-07-15 | Agent: CodeCraft | Status: RESOLVED

Root cause

The original UAT finding (MC #105765) conflated two separate, non-overlapping facts as one "CORS bug":

  1. The Ktor API's CORS_ORIGINS allowlist (azure-pipelines.yml:889) is deliberately scoped to the customer brand domains only (app.bilko.cloud, app.bilko.io, app.bilko.company, localhost). It correctly rejects unrecognized origins — the raw ACA FQDN and bilko-demo.alai.no — with a 403 BILKO-AUTH-003. This is intended access control, not a defect.
  2. bilko-demo.alai.no and bilko-demo-api.alai.no were dead Cloudflare CNAME records pointing at ghs.googlehosted.com (GCP era, dead since the 2026-06-15 Azure cutover). This was already tracked as DEPLOY-MAP.md OCD-11 and already declared "dead/retired for customer handoff" in the canonical docs/operations/DEMO-ACCESS.md (verified 2026-07-12).

The canonical customer/sales demo entry point, https://app.bilko.cloud/demo?country=HR, was never broken. Confirmed live before and after this change: HTTP 200, correct access-control-allow-origin header, zero console errors, zero network errors (Playwright chromium, screenshot in evidence).

Action taken

  • Deleted 2 dead DNS records from the alai.no Cloudflare zone: bilko-demo.alai.no and bilko-demo-api.alai.no (both CNAME → ghs.googlehosted.com).
  • No code, pipeline, ACA container app, revision, or CORS_ORIGINS config was changed.
  • No production traffic was touched — app.bilko.cloud/.io/.company and api.bilko.cloud/.io/.company all confirmed 200 before and after.
  • Updated DEPLOY-MAP.md: OCD-11 marked RESOLVED; 2 stale references to the retired hostnames corrected to point at the canonical demo URL.

Why repoint-through-Worker was rejected

Both DNS records were proxied=false (grey-clouded), so they could never reach the bilko-edge-proxy Cloudflare Worker's Host/SNI rewrite mechanism. The Worker's wrangler.toml routes are scoped to the bilko.io / bilko.cloud / bilko.company zones only — not alai.no. Extending that would require a code change, an azdo pipeline deploy, and a Workers-scoped Cloudflare API token (only a DNS/zone-scoped token was available at triage time). Disproportionate for a dead legacy alias already declared retired in canonical docs.

Verification

  • P2P pre-verifier (Company Mesh): thread mesh-thr-f05cd82e-5678-4178-bc2d-b5a678686c76, Proveo peer end-state PASS.
  • Live Playwright browser check on https://app.bilko.cloud/demo?country=HR: HTTP 200, 0 console errors, 0 network errors, screenshot captured.
  • DNS retirement confirmed via Cloudflare API (record count 0) and authoritative nameserver dig (empty answer) for both retired hostnames.
  • Prod safety confirmed: all 6 brand domain + health-check endpoints returned 200 post-change.

Evidence

~/system/evidence/105767/ — DNS before/after snapshots, Playwright result JSON + screenshot, direct-probe log, sha256-verified evidence manifest (evidence-105767.json).

References

  • MC #105765 (UAT synthesis that surfaced this) · MC #105767 (this task)
  • Bilko/DEPLOY-MAP.md OCD-11 · Bilko/docs/operations/DEMO-ACCESS.md