diff --git a/apps/queen-web/vite.config.ts b/apps/queen-web/vite.config.ts index 19bea13bc3..70edcaaad7 100644 --- a/apps/queen-web/vite.config.ts +++ b/apps/queen-web/vite.config.ts @@ -17,6 +17,22 @@ export default defineConfig({ }, }, }, + // Railway serves this through `npm start`, which is `vite preview`. Vite's + // preview server answers any Host it was not told about with 403 -- the + // DNS-rebinding guard that arrived in 6.0.9 and is on by default. The + // platform's own probe comes in as `healthcheck.railway.app`, so every + // deployment built cleanly, started, and then failed its healthcheck five + // times in thirty seconds. Four merges on 2026-09-21 never reached a running + // replica, and the build log said SUCCESS above the failure each time. + // + // A leading dot allows a domain and every subdomain, so one entry covers both + // the probe and the generated `*.up.railway.app` service domain -- neither of + // which is written down anywhere else, and the generated one can be reissued. + // The guard stays on for every other Host: `allowedHosts: true` would switch + // it off entirely, which is more than this failure asks for. + preview: { + allowedHosts: ['.railway.app'], + }, build: { outDir: 'dist', sourcemap: true,