Route53 REGISTER_DOMAIN fails sub-second on this AWS account, and the same cause would silently break domain AutoRenew #971
Labels
No labels
burndown-2026-06
burndown-2026-08
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
coherence-core
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
qa-fixture
role/advocate
role/director
role/exec
role/frontend
role/gamedev
role/human
role/platform
role/qa
role/science
role/sysadmin
state
ambient
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
coilyco-flight-deck/infrastructure#971
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Split out of
coilysiren/inbox#475, which owns the WHOIS exposure oncoilyco.ai. This issue owns the AWS-side failure, because it reaches past that one domain.The failure
Five
REGISTER_DOMAINoperations on 2026-08-27 againstcoilyco.com,coilyco.dev, andcoilyco.meall returned:Timing is the decisive signal. The solo retry was submitted at
16:11:48.201and failed at16:11:48.950, rejected in 0.75 seconds, before any registry round-trip.coilyco.aiby contrast reached the registry within a minute and its record was created. This is an account-side gate.Eliminated with evidence
DONEfor the accountACTIVEAVAILABLE, nothing half-landed.aiminutes earlier.meis a ccTLD like.aiand still failed, so gTLD-versus-ccTLD does not predict itupdate-domain-contact-privacyoncoilysiren.me, operation301353af-a0aa-429d-ba8e-39bbb5d26fa3, statusSUCCESSFUL. The service works on this account, on.me, at zero cost and with no state change. The earlier privacy-flag theory is dead.Surviving candidates
Neither is visible through the API. AWS returns the generic message by design.
The part that reaches past the original task
If the cause is the payment instrument, domain AutoRenew is exposed too. Both registered domains carry
AutoRenew: trueand would renew against the same instrument:coilysiren.me- expiry 2027-07-05, and this is the live production domaincoilyco.ai- expiry 2028-08-27, $137 renewalA renewal failure is quiet. It surfaces as a domain entering redemption, not as an alarm.
coilysiren.mecarries 88 records in its hosted zone and is the public surface, so losing it is the worst available outcome of an unchecked card.This is why the payment check is worth doing even though the three names are being registered elsewhere. The registration path was routed around. The renewal path cannot be.
Next actions
DescribeSeverityLevelsreturnsSubscriptionRequiredException, Premium Support required.Not in scope
Registering
coilyco.com,coilyco.dev, orcoilyco.me. Kai chose an external registrar for those, so they no longer depend on this being fixed. The WHOIS exposure oncoilyco.aistays withcoilysiren/inbox#475.Correction - the payment-instrument hypothesis in the issue body is wrong, and so is the AutoRenew alarm
Kai checked Billing on 2026-08-28 and reported it clean. Pushing on why the hypothesis was raised at all surfaced that the issue body over-weighted it against evidence already collected.
The evidence that was in hand and not reconciled
coilyco.airegistered successfully at15:01:48for $274, the largest of the four charges. The.comfailures begin at16:10:46, roughly one hour later, on the same account and the same payment instrument.AWS does not complete a domain registration without collecting payment, and that registration completed: the registry record exists, Gandi holds it, and it appears in
list-domainswith a 2028 expiry.The payment theory therefore requires an instrument that clears $274 to decline $16 an hour later. Nothing supports that, and Kai's Billing check independently contradicts it.
The reasoning flaw, named so it is not repeated
Sub-second rejection establishes that AWS refused the request internally, before any registry round-trip. It does not establish which internal check fired. Payment verification, fraud and risk scoring, and account eligibility all sit inside that window and all fail fast.
The issue body picked one of the three and described it as fitting the timing better. The timing is equally consistent with all three, and the successful $274 charge actively argues against the one chosen. That was inference presented as a ranked diagnosis.
Revised candidate ordering
registration-issuesupport case is the characteristic shape of an internal risk refusal. A first-time $274 domain purchase an hour earlier is a plausible trigger. This is now the leading candidate.Still eliminated with evidence, unchanged: registrant email verification, domain count limit, account standing, partial registration, velocity throttle, contact validity, TLD class, and the privacy protection service.
Retracting the AutoRenew risk
The issue body argued that
coilysiren.me(expiry 2027-07-05, 88 records, the public surface) andcoilyco.ai(expiry 2028-08-27) were exposed because AutoRenew runs against the same instrument.That concern was entirely downstream of the payment hypothesis and does not survive it. Billing is clean and the instrument demonstrably processed $274. Renewals charge that same working instrument. There is no silent-renewal-failure risk here, and no renewal guard is needed on the strength of this issue.
Retracting it explicitly rather than leaving it in the body, because an unretracted alarm about losing the production domain would keep drawing attention it does not deserve.
Recommended disposition
Close as not worth pursuing. The three names are being registered at Porkbun, so nothing depends on this. The only remaining path is a hand-filed support case (Premium Support is not on this account, so the Support API returns
SubscriptionRequiredException), and the payoff is an explanation for a path already routed around.Reopen if a future Route53 registration is actually wanted, or if a renewal ever fails, which would revive the payment question with real evidence behind it.
Reopening the privacy hypothesis - my earlier probe tested the wrong code path
New attempt on 2026-08-28 at
23:16:16,coilysiren.com, privacy on, using the corrected Oakland contact record.23:16:16.137, FAILED23:16:16.969AVAILABLETwo conclusions from this
The account contact address was not the cause. The AWS account contact was updated from the six-year-old Brooklyn record to the current Oakland address earlier the same session, which was the strongest remaining form of the payment and address-verification theory. Registration still fails identically. That theory is now weak on evidence rather than merely unproven.
My earlier "privacy hypothesis is dead" conclusion was wrong, and I am retracting it.
An earlier comment declared the privacy theory dead because an idempotent
update-domain-contact-privacyoncoilysiren.mereturnedSUCCESSFUL. That test was not decisive, and I presented it as though it were.Updating privacy on an already-registered domain and registering a new domain with the privacy flag set are different code paths. The probe proved Route53 can toggle privacy on an existing registration. It established nothing about whether the privacy service can be provisioned as part of
REGISTER_DOMAIN. I collapsed the two and reported a settled result from an unrelated success.The correlation, now six attempts with perfect separation
coilyco.ai- privacy off - SUCCEEDEDcoilyco.com- privacy on - FAILEDcoilyco.dev- privacy on - FAILEDcoilyco.me- privacy on - FAILEDcoilyco.comretry - privacy on - FAILEDcoilysiren.com- privacy on - FAILEDSix for six on a single variable, across two registrant names, four TLDs, both gTLD and ccTLD, two different days, and two different contact addresses. Every other variable has now moved at least once while the privacy flag stayed perfectly predictive.
This is the strongest candidate by a wide margin and it should not have been dismissed.
The decisive test, and why it is now cheap
Register
coilysiren.comwithPrivacyProtect*: false, then immediately callupdate-domain-contact-privacyto enable it.When this was first proposed on
coilysiren/inbox#475it was correctly refused, because the target was.ai, where no redaction exists at Route53 and a failed follow-up would strand a permanently public personal record. That risk is much smaller now:.comis a gTLD, so ICANN's registration data policy redacts contact data in RDAP and WHOIS at the registry level by default, independent of the registrar's privacy productupdate-domain-contact-privacyis proven working on this account, which is exactly what the earlier probe did establish, correctly scopedResidual risk is a brief window before the follow-up call, against a gTLD that redacts by default, carrying a mailbox address.
Status
Awaiting Kai's decision on running the privacy-off registration. Not attempting it unasked, since it is a deliberate choice to register without the privacy flag and the same experiment was explicitly deferred once already.
Privacy hypothesis killed on the correct code path. I was wrong to revive it.
coilysiren.com, privacy off, Oakland contact, 2026-08-28:23:24:21.433, FAILED23:24:22.364. 0.931 seconds.AVAILABLEThe previous comment argued the privacy flag was six-for-six predictive and called it the strongest candidate by a wide margin. It registered with the flag off and still failed. The correlation was coincidence produced by ordering, exactly as the first probe suggested before I talked myself out of it.
I have now been wrong twice on this issue: first the payment instrument, then the privacy flag, each time promoting a correlation to a diagnosis on timing evidence that could not distinguish between candidates. Recording that plainly because the pattern matters more than either wrong answer.
What seven attempts actually establish
One success, six failures, on this account:
coilyco.ai- 2026-08-27 15:01 - SUCCEEDEDcoilyco.com,coilyco.dev,coilyco.me,coilyco.comretry - 2026-08-27 16:10 to 16:20 - FAILED, two-year durationscoilysiren.comprivacy on - 2026-08-28 23:16 - FAILED, one-year durationcoilysiren.comprivacy off - 2026-08-28 23:24 - FAILED, one-year durationEliminated with direct evidence: registrant email verification, domain count limit, account standing, partial registration, velocity throttle, contact validity, TLD class (gTLD and ccTLD both fail), payment instrument (Kai confirmed billing clean, and a $274 charge cleared an hour before the first failure), contact address (failures both before and after the Brooklyn to Oakland correction), privacy flag (failures with it both on and off), and registration duration (failures at both one and two years).
Every failure is sub-second, 0.75 to 0.95 seconds, well before any registry round-trip. Nothing ever half-lands. Every attempted domain remains available.
What is left
The only surviving pattern is that the single success was
.aiand every failure was.com,.dev, or.me. That is one data point against six and is not a diagnosis.I have no further cheap test. Every variable reachable through the API has been moved. AWS returns a deliberately generic message and points at a support case, and the Support API is unavailable on this account (
DescribeSeverityLevelsreturnsSubscriptionRequiredException), so the case must be filed by hand in the web console.Status
REGISTER_DOMAINis effectively non-functional on this account for.com,.dev, and.me, cause unknown, not diagnosable from the API surface. Keeping this issue open as the record. An external registrar is the working path for any domain Kai actually wants.Console fails too,
.ainow fails too, and the shape is temporalKai attempted registration through the Route 53 console on 2026-08-27 at 23:30 Pacific. Three operations landed in the log and all failed:
5fab008f-05b9-43e9-b4d1-202a653a5d19-coilysiren.ai- FAILED29bbc549-0943-4c14-8e03-24f2991a628f-coilysiren.com- FAILEDccf22e49-27a5-43d5-ac5f-491e56868d60-coilysiren.dev- FAILEDTwo findings.
The console fails identically to the CLI. That eliminates every client-side explanation at once: request shape, SDK version, contact struct serialization, CLI flag handling. Two independent code paths, same refusal.
.ainow fails. It was the only TLD with a success on this account and the last surviving pattern in the previous comment. It is gone.coilysiren.aiwas refused exactly like the gTLDs.The actual shape: temporal, not categorical
Eleven
REGISTER_DOMAINoperations, one success, and the success is the first one:93696e2f-3ec0-4a89-93a3-9fb655a12ca9-coilyco.ai- submitted 15:01:48, completed 15:12:47 - the only success.com,.dev,.me, and.ai, across two days, two clients, both privacy states, both durations, and two contact addressesEvery attempt after 15:12:47 has failed. Nothing has succeeded since. The categorical hypotheses were all chasing structure inside the failure set when the real discriminator is that a gate went up on this account between
15:12:47and16:10:46Pacific on 2026-08-27, a 58-minute window.That is the question for AWS, and it is answerable only by them.
Support case, ready to file
Premium Support is not on this account, confirmed again:
support describe-severity-levelsreturnsSubscriptionRequiredException. Account and billing cases are still filable through the console on Basic support, which is where the error message's own link points.Link:
https://console.aws.amazon.com/support/home?region=us-east-1#/case/create?issueType=customer-service&serviceCode=service-domains&categoryCode=registration-issueSubject: Route 53 REGISTER_DOMAIN fails for every domain since 2026-08-27, sub-second generic error
Body:
Status
Blocked on AWS. Every API-reachable variable has been eliminated. Domains remain available and unregistered.