Domains
The rule
Every SVRBC domain is registered in the SVRBC Porkbun subaccount, and its DNS is served from there. Nothing SVRBC-owned lives in a personal Porkbun account, and nothing personal lives in the subaccount.
Porkbun’s API has no notion of subaccounts. Each account has its own API key pair, and a key only sees its own account’s domains. So the subaccount needs its own keys, kept beside the default account’s in ~/.env:
PORKBUN_SVRBC_API_KEY=pk1_…
PORKBUN_SVRBC_SECRET_KEY=sk1_…porkbun then reaches it as --profile svrbc.
Before concluding a domain isn’t there
Check every account. Porkbun answers a request for a domain held by another account with INVALID_DOMAIN and the hint “The domain name is invalid. Check the formatting.” The domain is fine; the key is the wrong one. porkbun now catches that error and names the profile that does hold the domain:
$ porkbun dns list svrbc.org
porkbun: svrbc.org is not in the default account; it is in profile svrbc. Rerun with --profile svrbc.To see everything at once:
porkbun domains --all # every configured account, with a profile columnPointing a subdomain at GitLab Pages
This is how developers.svrbc.org was set up:
In the project, add the domain with automatic HTTPS. With
glab:shglab api -X POST "projects/svrbc%2F<project>/pages/domains" \ -f domain=<name>.svrbc.org -F auto_ssl_enabled=trueThe response carries a
verification_code.Add the two records in the subaccount.
dns setis an upsert, so it’s safe to re-run:shporkbun --profile svrbc dns set svrbc.org CNAME <name> svrbc.gitlab.io porkbun --profile svrbc dns set svrbc.org TXT _gitlab-pages-verification-code.<name> \ gitlab-pages-verification-code=<code>Ask GitLab to verify. It runs the DNS check itself, then issues a Let’s Encrypt certificate within a few minutes:
shglab api -X PUT "projects/svrbc%2F<project>/pages/domains/<name>.svrbc.org/verify"
Moving a domain into the subaccount
- Disable DNSSEC before starting a transfer. Once a transfer is pending, the registry blocks every update, so neither registrar can remove the DS records. A signed domain whose DNS moves while its DS records stand resolves nowhere. Check with
dig +short DS <domain>. If it answers, disable DNSSEC and wait out the DS TTL first. - Export the zone from the old registrar’s panel, rather than probing for records. Probing finds only the names you think to guess.
- A DKIM
TXTrecord is one unbroken string. Control panels display a space at the 255-character split, and copying that space breaks DKIM silently. - Afterwards,
porkbun --profile svrbc check <domain>checks the delegation, the nameservers and public resolution in one go.