docs(dns): correct domain split — audience-based, not network-zone
This commit is contained in:
+31
-19
@@ -2,23 +2,42 @@
|
|||||||
|
|
||||||
**Last updated:** 2026-08-11
|
**Last updated:** 2026-08-11
|
||||||
|
|
||||||
## Split-Horizon DNS
|
## Domain Overview
|
||||||
|
|
||||||
The institute runs split-horizon DNS: internal and external services share
|
The institute uses two primary domains for hosted services. Both are publicly
|
||||||
different domain namespaces to prevent internal service URLs from leaking
|
accessible — there is no split-horizon or network-zone separation between them.
|
||||||
publicly.
|
The distinction is **audience-based**, determined per-service by the operator.
|
||||||
|
|
||||||
| Scope | Domain | Usage |
|
| Domain | Audience |
|
||||||
|-------|--------|-------|
|
|--------|----------|
|
||||||
| Internal | `pldyn.net` | Services accessible only inside the management subnet |
|
| `pldyn.net` | Operator and technical audience — dashboards, dev tools, infrastructure services |
|
||||||
| External | `sundialer.net` | Services exposed to the public internet |
|
| `sundialer.net` | Family-facing consumer services |
|
||||||
|
|
||||||
|
Domain assignment is not automatic. When deploying a new service, use judgement
|
||||||
|
based on the audience above. If the assignment is not obvious, ask the operator.
|
||||||
|
|
||||||
|
## Service Assignment Reference
|
||||||
|
|
||||||
|
Observable pattern from live Traefik configuration:
|
||||||
|
|
||||||
|
| Domain | Services |
|
||||||
|
|--------|----------|
|
||||||
|
| `sundialer.net` | audiolib/podcasts, boxoffice, dawarich, navidrome/music, oCIS, paperless-ngx |
|
||||||
|
| `pldyn.net` | beszel, bin, cdn, drawpile, gitea/vcs, immich/curator, lcarsdb, solidtime, traefik, vaultwarden, yaade, actual, omni-tools, daystrom-relay, pldyn.net (main site) |
|
||||||
|
|
||||||
|
### External Services (own domains — not subject to the split above)
|
||||||
|
|
||||||
|
- `sarimportauthority.org`
|
||||||
|
- `convectionand.coffee`
|
||||||
|
- `bluejeanblankie.com`
|
||||||
|
- `raccoonsoncaffeine.cool`
|
||||||
|
|
||||||
## Wildcard Patterns
|
## Wildcard Patterns
|
||||||
|
|
||||||
| Scope | Pattern |
|
| Domain | Pattern |
|
||||||
|-------|---------|
|
|--------|---------|
|
||||||
| Internal | `*.pldyn.net` |
|
| `pldyn.net` | `*.pldyn.net` |
|
||||||
| External | `*.sundialer.net` |
|
| `sundialer.net` | `*.sundialer.net` |
|
||||||
|
|
||||||
## Certificate Issuance
|
## Certificate Issuance
|
||||||
|
|
||||||
@@ -29,10 +48,3 @@ publicly.
|
|||||||
Traefik uses Cloudflare API credentials (stored as Swarm secrets / env vars,
|
Traefik uses Cloudflare API credentials (stored as Swarm secrets / env vars,
|
||||||
not in documentation) to complete the DNS challenge and obtain Let's Encrypt
|
not in documentation) to complete the DNS challenge and obtain Let's Encrypt
|
||||||
certificates for both domains.
|
certificates for both domains.
|
||||||
|
|
||||||
## Notes
|
|
||||||
|
|
||||||
- DNS records for `*.pldyn.net` resolve to internal IPs; they are not
|
|
||||||
publicly routable.
|
|
||||||
- DNS records for `*.sundialer.net` resolve to the public-facing IP managed
|
|
||||||
by Unifi / Cloudflare.
|
|
||||||
|
|||||||
Reference in New Issue
Block a user