Some checks failed
Architecture Governance / architecture (push) Has been cancelled
Tenant subdomains route through api.<base-domain>; nginx forwards the exact storefront host derived from the validated browser origin.
1.2 KiB
1.2 KiB
id, title, status, date, supersedes, tags
| id | title | status | date | supersedes | tags | ||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| ADR-0005 | Share one API host across storefront subdomains | active | 2026-08-20 |
|
|
ADR-0005: Share one API host across storefront subdomains
Context
One frontend bundle serves a base storefront domain and tenant subdomains. The API is shared at the base-domain level; a tenant subdomain must not create a nested API hostname.
Decision
example.com,store1.example.com, andwww.example.comall usehttps://api.example.com.- The complete storefront hostname remains the tenant hint. nginx validates the
browser Origin and forwards that hostname as
X-Storefront-Host. - Backend tenant lookup trusts that header only from the known proxy, verifies it against the domain registry, and binds authenticated sessions to the same tenant.
- Localhost continues through
/api.tenantApiBaseUrlsremains available for public-suffix or custom-domain exceptions.
Consequences
Tenant subdomains need no extra API DNS records or certificates. CORS must echo
the exact allowed storefront origin, while unknown or disabled domains still
receive 403 from the backend. The shared API Host alone cannot identify a
subdomain tenant.