Inspiration
DNS is one of those infrastructure layers that usually works quietly in the background — until one small mistake takes a website, API, email service, or product launch offline.
For independent developers and small teams, DNS changes are often still made manually: open a control panel, edit a record, save it, and hope everything is correct. There is rarely a safety workflow around that change.
LaunchGuard started from a simple question:
What if changing DNS felt more like deploying code safely?
Instead of giving AI unrestricted control over infrastructure, I wanted to build a system where AI could help understand intent and propose a solution, while deterministic validation, human approval, snapshots, verification, and rollback remained in control.
That became LaunchGuard: an AI-assisted DomainOps safety layer built around the Name.com CORE API.
What it does
LaunchGuard turns a natural language infrastructure request into a controlled DNS deployment workflow.
A user can:
- Search for a domain through Name.com.
- Check availability, registration price, and renewal price.
- Register the domain in the Name.com Sandbox.
- Describe a DNS change in natural language.
- Let Gemini generate a structured DNS plan.
- Run the proposed plan through deterministic safety validation.
- Review the plan and explicitly approve it.
- Automatically snapshot the current DNS state.
- Deploy the approved records through the Name.com CORE API.
- Verify that the expected DNS state was actually created.
- Roll back to the previous snapshot if needed.
- Verify that rollback successfully restored the original state.
The important design decision is that the AI never gets the final say.
Gemini proposes the DNS configuration, but LaunchGuard's validation engine and the human approval step determine whether that plan can move forward.
How I built it
LaunchGuard uses Python 3.12 and Flask for the backend, with a lightweight HTML, CSS, and vanilla JavaScript frontend.
The backend is divided into focused services for:
- Name.com CORE API communication
- Gemini-based DNS planning
- deterministic DNS validation
- SQLite snapshots
- safe deployment
- verification
- rollback
The Name.com integration is used throughout the workflow rather than as a single API call.
LaunchGuard performs domain availability checks, sandbox domain registration, DNS inspection, DNS record creation and deletion, post-deployment verification, and rollback operations through the Name.com CORE API.
For AI planning, LaunchGuard uses Google Gemini with structured output. Natural-language intent is converted into a predictable DNS plan containing fields such as record type, host, value, TTL, priority when applicable, risk level, and an explanation.
Before deployment, the deterministic validator checks conditions such as valid IPv4 and IPv6 addresses, allowed record types, minimum TTL values, hostname validity, MX priorities, duplicate records, and CNAME conflicts.
Only after validation does the interface present the human approval step.
Immediately before writing DNS changes, LaunchGuard stores the current state in SQLite. After deployment, it reads the state back from Name.com and verifies the result.
Rollback follows the same safety philosophy: it compares the snapshot with the current state, removes unexpected records, restores missing ones, and performs another verification.
Challenges
One of the biggest challenges was designing the project so AI assistance did not become AI autonomy.
DNS infrastructure is too sensitive for a model response to be executed blindly. I had to separate probabilistic planning from deterministic enforcement.
Another challenge was making rollback more than a visual feature. It needed to restore actual Name.com Sandbox DNS state and then independently verify that restoration.
Deployment also introduced practical infrastructure challenges. LaunchGuard was moved from a Windows development environment to an Ubuntu production server running CloudPanel, Nginx, Gunicorn, systemd, and Let's Encrypt.
The final application is publicly accessible over HTTPS while Gunicorn remains bound only to localhost behind Nginx.
Accomplishments that I'm proud of
The part I am most proud of is that the demo is not simulated.
The complete workflow has been tested end-to-end against the Name.com Sandbox:
domain discovery → registration → Gemini plan → validation → human approval → snapshot → deployment → verification → rollback → final verification
During final production testing, LaunchGuard created a TXT record through Name.com, verified the deployment, rolled back to the previous snapshot, and then directly queried Name.com again to confirm that the DNS state had returned to zero records.
That made the rollback engine a real infrastructure operation rather than just a UI concept.
What I learned
Building LaunchGuard reinforced an important principle for AI infrastructure tooling:
AI is strongest when it helps humans reason about intent, while deterministic systems enforce safety.
I also learned how much value can come from combining several relatively simple mechanisms — structured AI output, validation, snapshots, API operations, verification, and explicit approval — into one coherent workflow.
The result feels less like a traditional DNS editor and more like a small deployment safety system for domain infrastructure.
What's next for LaunchGuard
The hackathon MVP intentionally focuses on a narrow, reliable workflow.
Future versions could extend the same safety model to:
- multi-domain environments
- reusable deployment templates
- staged DNS rollouts
- DNS drift detection
- approval workflows for teams
- audit history
- automatic rollback policies
- production Name.com accounts
- infrastructure-as-code integrations
- monitoring and alerting after DNS deployment
The broader vision is to make domain infrastructure changes safer and more understandable without removing human control.
Log in or sign up for Devpost to join the conversation.