Append-only log of confirmed defects in this repo that are not fixed yet.
Same rules as _internal/UPSTREAM_BUGS.md: never rewrite an entry — a later
finding is appended to it as a dated **Update YYYY-MM-DD:** line. Delete an
entry only by moving it to a Closed section with the fixing sha.
Fix ownership lives in AGENTS.md: defects reported by teploy-dash or
teploy-ship that trace into this binary are ours, and a workaround landed up
there without an entry here is how the same bug gets paid for twice. When a
BUGS.md entry is fixed, say so in the fixing commit message so the two can be
found from each other.
## YYYY-MM-DD — short title
- **Area:** cli | config | caddy | dns | deploy | other
- **Symptom:** what was observed
- **Suspected component:** file/function, with line references as of the report date
- **Reproduction:** minimal steps or case
- **Workaround (if any):** what callers can do until it is fixed
- **Reporter:** agent/session identifier
- **Status:** open | fixed (<sha>)
- Area: cli (validate, deploy) + dns
- Symptom: any
teploy.ymlwith a multi-hostdomain:list (e.g.domain: "dreamlucidgroup.com, www.dreamlucidgroup.com") getsDNS: could not resolve domain a.com, www.a.com: no such host— the whole comma-joined string is looked up as if it were one hostname. Invalidatethis is a warning; indeployit aborts the deploy, even when every listed host resolves correctly. - Suspected component: two call sites pass
appCfg.Domaintodns.Validatewithout splitting it first:internal/cli/validate.go:107—dns.Validate(appCfg.Domain, host, nil)internal/cli/deploy.go:441— same call, fatal on error (dns.Validateitself is fine — it just doesnet.LookupHoston what it is given.) The rest of the CLI already splits correctly:nonPublicDomainWarnings(validate.go:146) splits on,, andsplitDomains(remove.go:120) is the trimmed per-host parser.
- Reproduction:
domain: "example.com, www.example.com"where both hosts resolve; runteploy validate(false-positive DNS warning) orteploy deploy(aborts). Observed in the wild deployinghardware-site(dreamlucidgroup.com + www) to deploy-ovh on 2026-09-08; both hosts verified viadigto point at the server before bypassing. - Workaround:
--skip-dns-checkafter verifying each host's DNS manually. No code workaround; both hosts must otherwise be dropped to single-host form. - Fix sketch: route both call sites through
splitDomains(hoist it out ofremove.goif the package layout prefers) and validate each host individually, reporting the failing host by name. Add a unit test with a two-host domain string next to the existingnonPublicDomainWarningsandsplitDomainstests. - Reporter: hardware-site session, 2026-09-08.
- Status: open