# v1.0.0 → v1.0.1 — the whole freeze delta, served so a stranger can check it. # # The demo says v1 stays 'frozen and untouched'. The v1 repo is PRIVATE, so round 7's # evaluators could not verify that clause and rightly refused to take it on testimony. # This file is the entire diff between the two tags. Reproduce it, if you have access: # git -C workspaces/gars-demo diff v1.0.0 v1.0.1 # Tag objects: v1.0.0 -> 87204b35f4426f7e39381375d2ca1d3795eee88c # v1.0.1 -> 02e1722c9f95466fc1c81bdff02f330f03b2159a # Nothing under api/, gars_runtime/, containers/, tools/ or traces/ appears below. # diff --git a/README.md b/README.md index 26c2875..821fa9e 100644 --- a/README.md +++ b/README.md @@ -2,7 +2,7 @@ Interactive portfolio demo for [GARS](https://github.com/javrodriguez/genomics-agentic-research-system) — replay real agent runs (stage contracts, the filesystem state machine, the human-in-the-loop gates) in the browser, with a token-gated live lane for interviews. -**Live:** https://gars.javrodriguez.dev/ +**Live:** https://v1.gars.javrodriguez.dev/ — v1, frozen at `v1.0.0`. The front door, https://gars.javrodriguez.dev/, has served v2 since 4 Sep 2026. - **What** — recorded real GARS runs (`traces/`, format in `traces/FORMAT.md`) served by FastAPI and replayed in a Next.js three-pane UI. Replay core is always-on; the live lane is gated. - **How to run** — local: `uv run --directory api uvicorn app.main:app` after `scripts/build_ui.sh`, or `docker run -p 8080:8080` the image. Deploy: `scripts/deploy.sh` (AWS creds in `.env`, IaC in `infra/`). Recording tooling: `tools/` (stdlib only). diff --git a/infra/cdn.tf b/infra/cdn.tf index abaa693..9e23d97 100644 --- a/infra/cdn.tf +++ b/infra/cdn.tf @@ -16,6 +16,18 @@ resource "aws_acm_certificate_validation" "root" { validation_record_fqdns = [for r in aws_route53_record.cert_validation : r.fqdn] } +# Gate 2: v1 now answers at v1.gars.javrodriguez.dev, and a wildcard matches ONE label — +# v1's own certificate (*.javrodriguez.dev) covers gars.javrodriguez.dev and not one level +# deeper. v2's certificate (gars.javrodriguez.dev + *.gars.javrodriguez.dev) was issued to +# cover both the apex and v1.gars for exactly this swap. Looked up by domain, never pasted +# as an ARN: a re-issued certificate flows through on the next apply. v1's own certificate +# resource stays declared and issued; nothing here destroys it. +data "aws_acm_certificate" "gars_wildcard" { + domain = "gars.${var.root_domain}" + statuses = ["ISSUED"] + most_recent = true +} + locals { demo_domain = "${var.demo_subdomain}.${var.root_domain}" # function_url is "https://.lambda-url..on.aws/" — CloudFront @@ -66,7 +78,7 @@ resource "aws_cloudfront_distribution" "demo" { } viewer_certificate { - acm_certificate_arn = aws_acm_certificate_validation.root.certificate_arn + acm_certificate_arn = data.aws_acm_certificate.gars_wildcard.arn ssl_support_method = "sni-only" minimum_protocol_version = "TLSv1.2_2021" } diff --git a/infra/dns.tf b/infra/dns.tf index b0ddba0..202413b 100644 --- a/infra/dns.tf +++ b/infra/dns.tf @@ -15,7 +15,10 @@ variable "root_domain" { variable "demo_subdomain" { type = string - default = "gars" # the demo lives at gars.javrodriguez.dev + # Gate 2, 4 Sep 2026: v2 took the front door, so v1 answers at v1.gars.javrodriguez.dev. + # This is the DEFAULT and not a -var on purpose: deploy.sh passes no subdomain, so a + # value handed in on the command line would be undone by the next routine redeploy. + default = "v1.gars" } resource "aws_route53_zone" "root" { diff --git a/src/app/layout.tsx b/src/app/layout.tsx index 073f39d..64e0ac5 100644 --- a/src/app/layout.tsx +++ b/src/app/layout.tsx @@ -19,7 +19,7 @@ const DESCRIPTION = "Built by Javier Rodriguez Hernaez."; export const metadata: Metadata = { - metadataBase: new URL("https://gars.javrodriguez.dev"), + metadataBase: new URL("https://v1.gars.javrodriguez.dev"), alternates: { canonical: "./" }, // resolves per page against metadataBase title: TITLE, description: DESCRIPTION,