docs(dns): correct domain split — audience-based, not network-zone
This commit is contained in:
+31
-19
@@ -2,23 +2,42 @@
|
||||
|
||||
**Last updated:** 2026-08-11
|
||||
|
||||
## Split-Horizon DNS
|
||||
## Domain Overview
|
||||
|
||||
The institute runs split-horizon DNS: internal and external services share
|
||||
different domain namespaces to prevent internal service URLs from leaking
|
||||
publicly.
|
||||
The institute uses two primary domains for hosted services. Both are publicly
|
||||
accessible — there is no split-horizon or network-zone separation between them.
|
||||
The distinction is **audience-based**, determined per-service by the operator.
|
||||
|
||||
| Scope | Domain | Usage |
|
||||
|-------|--------|-------|
|
||||
| Internal | `pldyn.net` | Services accessible only inside the management subnet |
|
||||
| External | `sundialer.net` | Services exposed to the public internet |
|
||||
| Domain | Audience |
|
||||
|--------|----------|
|
||||
| `pldyn.net` | Operator and technical audience — dashboards, dev tools, infrastructure services |
|
||||
| `sundialer.net` | Family-facing consumer services |
|
||||
|
||||
Domain assignment is not automatic. When deploying a new service, use judgement
|
||||
based on the audience above. If the assignment is not obvious, ask the operator.
|
||||
|
||||
## Service Assignment Reference
|
||||
|
||||
Observable pattern from live Traefik configuration:
|
||||
|
||||
| Domain | Services |
|
||||
|--------|----------|
|
||||
| `sundialer.net` | audiolib/podcasts, boxoffice, dawarich, navidrome/music, oCIS, paperless-ngx |
|
||||
| `pldyn.net` | beszel, bin, cdn, drawpile, gitea/vcs, immich/curator, lcarsdb, solidtime, traefik, vaultwarden, yaade, actual, omni-tools, daystrom-relay, pldyn.net (main site) |
|
||||
|
||||
### External Services (own domains — not subject to the split above)
|
||||
|
||||
- `sarimportauthority.org`
|
||||
- `convectionand.coffee`
|
||||
- `bluejeanblankie.com`
|
||||
- `raccoonsoncaffeine.cool`
|
||||
|
||||
## Wildcard Patterns
|
||||
|
||||
| Scope | Pattern |
|
||||
|-------|---------|
|
||||
| Internal | `*.pldyn.net` |
|
||||
| External | `*.sundialer.net` |
|
||||
| Domain | Pattern |
|
||||
|--------|---------|
|
||||
| `pldyn.net` | `*.pldyn.net` |
|
||||
| `sundialer.net` | `*.sundialer.net` |
|
||||
|
||||
## Certificate Issuance
|
||||
|
||||
@@ -29,10 +48,3 @@ publicly.
|
||||
Traefik uses Cloudflare API credentials (stored as Swarm secrets / env vars,
|
||||
not in documentation) to complete the DNS challenge and obtain Let's Encrypt
|
||||
certificates for both domains.
|
||||
|
||||
## Notes
|
||||
|
||||
- DNS records for `*.pldyn.net` resolve to internal IPs; they are not
|
||||
publicly routable.
|
||||
- DNS records for `*.sundialer.net` resolve to the public-facing IP managed
|
||||
by Unifi / Cloudflare.
|
||||
|
||||
Reference in New Issue
Block a user