Skip to content

feat!: move to r9lab.io and rename the product to R9lab - #417

Merged
simonvanlierde merged 35 commits into
mainfrom
feat/r9lab-domain
Oct 10, 2026
Merged

simonvanlierde merged 35 commits into
mainfrom
feat/r9lab-domain

Conversation

@simonvanlierde

Copy link
Copy Markdown
Contributor

Moves the public domain to r9lab.io and renames the product to R9lab in all user-facing text. cml-relab.org keeps working through redirects, and existing sessions end once because the session cookies are renamed.

  • Infra: each Cloudflare zone gets its own OpenTofu workspace with a check that the zone id matches the zone name. The previous zone gets an opt-in redirect ruleset per environment. info@ is forwarded with Email Routing. The edge serves r9lab.io, keeping the old tunnel hostnames in its ingress during the switch.
  • Auth: session and OAuth CSRF cookies are now __Host-r9lab-*; the old names are no longer accepted.
  • URLs, contact address and copy point at r9lab.io and say R9lab; just smoke-redirects checks the redirects after each cutover step.

Part of #410.

- rename the auth, refresh and OAuth CSRF cookies to __Host-r9lab-auth, __Host-r9lab-refresh and __Host-r9lab-oauth-csrf
- the old names are no longer read, so existing sessions end once
- regenerate the public OpenAPI schema and the app API types
The old zone's redirect ruleset covered both environments, so cutting over staging also redirected the prod hosts to names that do not exist yet. redirect_environments (default both) limits the rules to the environments being moved.
An unknown environment produced no routes, so the check passed with nothing tested. It now exits 2 before any request.
The edge root defaults to r9lab.io, so an old zone id left in the environment would put the records in the wrong zone. The plan now fails when the id and name disagree.
- cover both zones in the two-roots overview, with one zone-root workspace per zone
- add the redirect cutover per environment, the pre-window ruleset check and the post-cutover tfvars
- state the expected plan after the first-run state move, and the case where the workspace exists
- apply the new zone's rulesets before its records, and keep a proxied record on the old zone
- add the token rows for redirects, Email Routing and the zone id check
- write "an R9lab" in the duplicate-account email and the codebook description
- join the split Changed list and drop a maintainer-only note
- note the per-environment redirects and the edge root's zone id check
Comment thread backend/tests/unit/auth/test_auth_cookie_scope.py Fixed
- point the .github pages at docs.r9lab.io and the info@r9lab.io contact
- rename the product to R9lab in those pages and the devcontainer greetings
- add a test that keeps README.md and the .github pages off the old domain
- redirect_environments has no default and must be set whenever redirect_to_zone_name is,
  so a staging apply cannot redirect prod by leaving it out
- legacy_zone_name defaults to the previous zone during the move, so an apply without it
  keeps the old hosts in the tunnel ingress
- commit the old zone's tfvars as each environment's redirects land
After a correct first hop, request the new host once more and fail when it redirects
back to the old zone, which a leftover forwarding rule on the new zone would do.
- assert every old host redirects to its own prefix on the new zone, from literal pairs
- check that the smoke script's host list matches infra/cloudflare/hostnames.tf
A zone with email_forwards also gets a _dmarc TXT record with p=none and aggregate reports
to info@ on that zone. DKIM and SPF for outbound mail stay with the sending provider.
- run the zone move per environment: remove the interim forwarding for its hosts right
  before its edge apply, and build images only after that apply
- keep the cutover window to one YES: plan the redirect apply right before the .env switch,
  check the Environment's API_PUBLIC_URL, run Deploy Sites, then apply
- roll back the Environment URL variables by hand, since the old records are unmanaged
- apply the moved old-zone state's description-only plan at the state move
- the committed old-zone tfvars overrides TF_VAR_*, so prod's redirect apply edits it to
  both environments and commits the edit once the apply lands
- keep the placeholder records and narrow the interim redirect rules to the prod hosts
  before staging's edge apply, so prod hosts keep forwarding until their own apply
- describe redirect_environments as an empty default with a validation
* origin/main:
  feat(app): expand the component tree to any depth with a weight total (#416)
  test(backend): pin clamav protocol and upload quota ledger results (#415)
  fix(app): remove two traps from the next Expo and React Native upgrade (#414)

# Conflicts:
#	CHANGELOG.md
#	app/src/types/openapi.json
@simonvanlierde
simonvanlierde merged commit 2cb70b0 into main Oct 10, 2026
23 checks passed
@simonvanlierde
simonvanlierde deleted the feat/r9lab-domain branch October 10, 2026 19:46
simonvanlierde added a commit that referenced this pull request Oct 10, 2026
…ertions

* origin/main:
  feat!: move to r9lab.io and rename the product to R9lab (#417)

# Conflicts:
#	backend/tests/integration/api/auth/test_oauth_callbacks.py
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants