No top-level domain appears anywhere in the source.
Each surface's URL arrives as configuration, because which domain a deployment answers on is an environment fact, not a code fact. Two environments, two domains, one build.
The trap this avoids is subtle: the moment a hostname is written into code, environment differences start being expressed as conditionals around that hostname, and those conditionals are the ones that fail open in whichever environment nobody tests.
⚠️ A related rule that is easy to get wrong: a surface's configured URL is a surface base. Paths that belong to the server rather than to a surface — health checks, status, well-known documents — answer on every surface host and hang off the host, not off the surface base. Appending them to a surface URL happens to work right up until a surface is mounted somewhere other than the root.