docs(dns): correct domain split — audience-based, not network-zone

This commit is contained in:
2026-08-11 11:57:51 +00:00
parent 97fbbabb79
commit 05edddf996
+31 -19
View File
@@ -2,23 +2,42 @@
**Last updated:** 2026-08-11 **Last updated:** 2026-08-11
## Split-Horizon DNS ## Domain Overview
The institute runs split-horizon DNS: internal and external services share The institute uses two primary domains for hosted services. Both are publicly
different domain namespaces to prevent internal service URLs from leaking accessible — there is no split-horizon or network-zone separation between them.
publicly. The distinction is **audience-based**, determined per-service by the operator.
| Scope | Domain | Usage | | Domain | Audience |
|-------|--------|-------| |--------|----------|
| Internal | `pldyn.net` | Services accessible only inside the management subnet | | `pldyn.net` | Operator and technical audience — dashboards, dev tools, infrastructure services |
| External | `sundialer.net` | Services exposed to the public internet | | `sundialer.net` | Family-facing consumer services |
Domain assignment is not automatic. When deploying a new service, use judgement
based on the audience above. If the assignment is not obvious, ask the operator.
## Service Assignment Reference
Observable pattern from live Traefik configuration:
| Domain | Services |
|--------|----------|
| `sundialer.net` | audiolib/podcasts, boxoffice, dawarich, navidrome/music, oCIS, paperless-ngx |
| `pldyn.net` | beszel, bin, cdn, drawpile, gitea/vcs, immich/curator, lcarsdb, solidtime, traefik, vaultwarden, yaade, actual, omni-tools, daystrom-relay, pldyn.net (main site) |
### External Services (own domains — not subject to the split above)
- `sarimportauthority.org`
- `convectionand.coffee`
- `bluejeanblankie.com`
- `raccoonsoncaffeine.cool`
## Wildcard Patterns ## Wildcard Patterns
| Scope | Pattern | | Domain | Pattern |
|-------|---------| |--------|---------|
| Internal | `*.pldyn.net` | | `pldyn.net` | `*.pldyn.net` |
| External | `*.sundialer.net` | | `sundialer.net` | `*.sundialer.net` |
## Certificate Issuance ## Certificate Issuance
@@ -29,10 +48,3 @@ publicly.
Traefik uses Cloudflare API credentials (stored as Swarm secrets / env vars, Traefik uses Cloudflare API credentials (stored as Swarm secrets / env vars,
not in documentation) to complete the DNS challenge and obtain Let's Encrypt not in documentation) to complete the DNS challenge and obtain Let's Encrypt
certificates for both domains. certificates for both domains.
## Notes
- DNS records for `*.pldyn.net` resolve to internal IPs; they are not
publicly routable.
- DNS records for `*.sundialer.net` resolve to the public-facing IP managed
by Unifi / Cloudflare.