Skip to content

Domains ​

The rule ​

Every SVRBC domain is registered in the SVRBC Porkbun subaccount, and its DNS is served from there. Nothing SVRBC-owned lives in a personal Porkbun account, and nothing personal lives in the subaccount.

Porkbun’s API has no notion of subaccounts. Each account has its own API key pair, and a key only sees its own account’s domains. So the subaccount needs its own keys, kept beside the default account’s in ~/.env:

sh
PORKBUN_SVRBC_API_KEY=pk1_…
PORKBUN_SVRBC_SECRET_KEY=sk1_…

porkbun then reaches it as --profile svrbc.

Before concluding a domain isn’t there ​

Check every account. Porkbun answers a request for a domain held by another account with INVALID_DOMAIN and the hint “The domain name is invalid. Check the formatting.” The domain is fine; the key is the wrong one. porkbun now catches that error and names the profile that does hold the domain:

text
$ porkbun dns list svrbc.org
porkbun: svrbc.org is not in the default account; it is in profile svrbc. Rerun with --profile svrbc.

To see everything at once:

sh
porkbun domains --all     # every configured account, with a profile column

Pointing a subdomain at GitLab Pages ​

This is how developers.svrbc.org was set up:

  1. In the project, add the domain with automatic HTTPS. With glab:

    sh
    glab api -X POST "projects/svrbc%2F<project>/pages/domains" \
      -f domain=<name>.svrbc.org -F auto_ssl_enabled=true

    The response carries a verification_code.

  2. Add the two records in the subaccount. dns set is an upsert, so it’s safe to re-run:

    sh
    porkbun --profile svrbc dns set svrbc.org CNAME <name> svrbc.gitlab.io
    porkbun --profile svrbc dns set svrbc.org TXT _gitlab-pages-verification-code.<name> \
      gitlab-pages-verification-code=<code>
  3. Ask GitLab to verify. It runs the DNS check itself, then issues a Let’s Encrypt certificate within a few minutes:

    sh
    glab api -X PUT "projects/svrbc%2F<project>/pages/domains/<name>.svrbc.org/verify"

Moving a domain into the subaccount ​

  • Disable DNSSEC before starting a transfer. Once a transfer is pending, the registry blocks every update, so neither registrar can remove the DS records. A signed domain whose DNS moves while its DS records stand resolves nowhere. Check with dig +short DS <domain>. If it answers, disable DNSSEC and wait out the DS TTL first.
  • Export the zone from the old registrar’s panel, rather than probing for records. Probing finds only the names you think to guess.
  • A DKIM TXT record is one unbroken string. Control panels display a space at the 255-character split, and copying that space breaks DKIM silently.
  • Afterwards, porkbun --profile svrbc check <domain> checks the delegation, the nameservers and public resolution in one go.