Production domain and edge runbook

The canonical production origin is https://lycato.app. Firebase project lycatoprod (project number 953136827428) owns the Hosting site and Authentication configuration. www.lycato.app is a Firebase Hosting redirect to the apex.

Firebase custom-domain resources

The Hosting API resources are:

The canonical staged DNS values are:

Type Name Content Initial proxy state
A lycato.app 199.36.158.100 DNS only
TXT lycato.app hosting-site=lycatoprod not proxyable
CNAME www.lycato.app lycatoprod.web.app DNS only

As verified on 27 August 2026, the apex is already proxied through Cloudflare, Firebase reports HOST_ACTIVE / OWNERSHIP_ACTIVE, and its certificate is propagating. The ownership TXT is present. www is NXDOMAIN; Firebase still requires its CNAME and reports HOST_UNHOSTED / OWNERSHIP_MISSING.

Add new address records DNS-only until their custom-domain resources report HOST_ACTIVE and their certificates report CERT_ACTIVE. This lets Firebase observe the required records and issue its origin certificates. Do not remove the TXT ownership record after activation.

Optional Cloudflare proxy phase

Proxy a new host only after Firebase certificate activation. The required edge posture is:

Cloudflare normally forwards the visitor Host; Firebase uses that host to select the custom-domain mapping. If a proxy rule overrides it with lycatoprod.web.app, redirects, cookies, canonical URLs, and OAuth callbacks can cross origins and must be treated as a failed deployment.

After enabling the proxy, re-check both Firebase domain resources. If either returns HOST_MISMATCH or certificate renewal issues, return the address record to DNS-only immediately. DNS-only remains a fully supported production posture; Cloudflare still remains the authoritative DNS provider.

Authentication domain contract

Firebase Authentication authorizes lycato.app, www.lycato.app, lycatoprod.firebaseapp.com, lycatoprod.web.app, and localhost. The browser uses lycato.app as authDomain on the custom domain and sends production verification/recovery continuations to the canonical apex. Google OAuth redirect handlers are registered at https://<authorized-domain>/__/auth/handler.

Verification

dig +short NS lycato.app
dig +short A lycato.app
dig +short TXT lycato.app
dig +short CNAME www.lycato.app
curl --fail --location https://lycato.app/
curl --fail --location https://www.lycato.app/
curl --fail https://lycato.app/__/firebase/init.json

The apex must serve the current Hosting release with the repository CSP and HSTS headers. The www request must land on the apex, and the init document must name lycatoprod.