# MC #105767 — Bilko Demo CORS/DNS Fix (OCD-11 Resolved)

# MC #105767 — Bilko Demo Env CORS/API-host + DNS Retirement (OCD-11 closed)

**Date:** 2026-07-15 | **Agent:** CodeCraft | **Status:** RESOLVED

## Root cause

The original UAT finding (MC #105765) conflated two separate, non-overlapping facts as one "CORS bug":

1. The Ktor API's `CORS_ORIGINS` allowlist (`azure-pipelines.yml:889`) is deliberately scoped to
   the customer brand domains only (`app.bilko.cloud`, `app.bilko.io`, `app.bilko.company`,
   `localhost`). It correctly rejects unrecognized origins — the raw ACA FQDN and
   `bilko-demo.alai.no` — with a 403 `BILKO-AUTH-003`. **This is intended access control, not a
   defect.**
2. `bilko-demo.alai.no` and `bilko-demo-api.alai.no` were dead Cloudflare CNAME records pointing
   at `ghs.googlehosted.com` (GCP era, dead since the 2026-06-15 Azure cutover). This was already
   tracked as `DEPLOY-MAP.md` OCD-11 and already declared "dead/retired for customer handoff" in
   the canonical `docs/operations/DEMO-ACCESS.md` (verified 2026-07-12).

The canonical customer/sales demo entry point, `https://app.bilko.cloud/demo?country=HR`, was
**never broken**. Confirmed live before and after this change: HTTP 200, correct
`access-control-allow-origin` header, zero console errors, zero network errors (Playwright
chromium, screenshot in evidence).

## Action taken

- Deleted 2 dead DNS records from the `alai.no` Cloudflare zone: `bilko-demo.alai.no` and
  `bilko-demo-api.alai.no` (both CNAME → `ghs.googlehosted.com`).
- No code, pipeline, ACA container app, revision, or `CORS_ORIGINS` config was changed.
- No production traffic was touched — `app.bilko.cloud/.io/.company` and
  `api.bilko.cloud/.io/.company` all confirmed 200 before and after.
- Updated `DEPLOY-MAP.md`: OCD-11 marked RESOLVED; 2 stale references to the retired hostnames
  corrected to point at the canonical demo URL.

## Why repoint-through-Worker was rejected

Both DNS records were `proxied=false` (grey-clouded), so they could never reach the
`bilko-edge-proxy` Cloudflare Worker's Host/SNI rewrite mechanism. The Worker's `wrangler.toml`
routes are scoped to the `bilko.io` / `bilko.cloud` / `bilko.company` zones only — not `alai.no`.
Extending that would require a code change, an azdo pipeline deploy, and a Workers-scoped
Cloudflare API token (only a DNS/zone-scoped token was available at triage time). Disproportionate
for a dead legacy alias already declared retired in canonical docs.

## Verification

- **P2P pre-verifier (Company Mesh):** thread `mesh-thr-f05cd82e-5678-4178-bc2d-b5a678686c76`,
  Proveo peer end-state PASS.
- **Live Playwright browser check** on `https://app.bilko.cloud/demo?country=HR`: HTTP 200, 0
  console errors, 0 network errors, screenshot captured.
- **DNS retirement confirmed** via Cloudflare API (record count 0) and authoritative nameserver
  `dig` (empty answer) for both retired hostnames.
- **Prod safety confirmed:** all 6 brand domain + health-check endpoints returned 200
  post-change.

## Evidence

`~/system/evidence/105767/` — DNS before/after snapshots, Playwright result JSON + screenshot,
direct-probe log, sha256-verified evidence manifest (`evidence-105767.json`).

## References

- MC #105765 (UAT synthesis that surfaced this) · MC #105767 (this task)
- `Bilko/DEPLOY-MAP.md` OCD-11 · `Bilko/docs/operations/DEMO-ACCESS.md`