[management] Prevent deleting custom domains used by services (#7515)

Deleting a custom domain released its name while services still pointed
at it, leaving them on a namespace the account no longer held.

Deletion now refuses with 412 when a service in the same account uses the
domain or a subdomain, including disabled ones. Service writes revalidate
authorization inside their transaction and hold a shared lock on the
matching registrations, so a delete racing a create cannot strand either.
The dependency lookup is account-scoped: registrations are unique by name,
so another account can hold team.example.com under example.com and its
services are authorized by its own registration.
This commit is contained in:
Maycon Santos
2026-09-28 14:14:32 +02:00
committed by GitHub
parent c6aa6c232e
commit 979571a99f
12 changed files with 424 additions and 10 deletions
+5
View File
@@ -26,3 +26,8 @@ window. Restarting management does not extend a previously assigned deadline.
Registrations with existing services, including services using subdomains, are
retained for operator review. Management logs their account and domain IDs so
an operator can identify and resolve those dependencies before cleanup.
Manual deletion is also refused while any service uses the domain or a subdomain,
including disabled services. Delete those services or move them to another domain
before removing the registration. A refused deletion returns HTTP 412 and leaves
the domain and its services unchanged; no deletion activity event is recorded.