diff --git a/infrastructure/dns.md b/infrastructure/dns.md index 7a63145..bed8079 100644 --- a/infrastructure/dns.md +++ b/infrastructure/dns.md @@ -2,23 +2,42 @@ **Last updated:** 2026-08-11 -## Split-Horizon DNS +## Domain Overview -The institute runs split-horizon DNS: internal and external services share -different domain namespaces to prevent internal service URLs from leaking -publicly. +The institute uses two primary domains for hosted services. Both are publicly +accessible — there is no split-horizon or network-zone separation between them. +The distinction is **audience-based**, determined per-service by the operator. -| Scope | Domain | Usage | -|-------|--------|-------| -| Internal | `pldyn.net` | Services accessible only inside the management subnet | -| External | `sundialer.net` | Services exposed to the public internet | +| Domain | Audience | +|--------|----------| +| `pldyn.net` | Operator and technical audience — dashboards, dev tools, infrastructure services | +| `sundialer.net` | Family-facing consumer services | + +Domain assignment is not automatic. When deploying a new service, use judgement +based on the audience above. If the assignment is not obvious, ask the operator. + +## Service Assignment Reference + +Observable pattern from live Traefik configuration: + +| Domain | Services | +|--------|----------| +| `sundialer.net` | audiolib/podcasts, boxoffice, dawarich, navidrome/music, oCIS, paperless-ngx | +| `pldyn.net` | beszel, bin, cdn, drawpile, gitea/vcs, immich/curator, lcarsdb, solidtime, traefik, vaultwarden, yaade, actual, omni-tools, daystrom-relay, pldyn.net (main site) | + +### External Services (own domains — not subject to the split above) + +- `sarimportauthority.org` +- `convectionand.coffee` +- `bluejeanblankie.com` +- `raccoonsoncaffeine.cool` ## Wildcard Patterns -| Scope | Pattern | -|-------|---------| -| Internal | `*.pldyn.net` | -| External | `*.sundialer.net` | +| Domain | Pattern | +|--------|---------| +| `pldyn.net` | `*.pldyn.net` | +| `sundialer.net` | `*.sundialer.net` | ## Certificate Issuance @@ -29,10 +48,3 @@ publicly. Traefik uses Cloudflare API credentials (stored as Swarm secrets / env vars, not in documentation) to complete the DNS challenge and obtain Let's Encrypt certificates for both domains. - -## Notes - -- DNS records for `*.pldyn.net` resolve to internal IPs; they are not - publicly routable. -- DNS records for `*.sundialer.net` resolve to the public-facing IP managed - by Unifi / Cloudflare.