docs(dns): correct domain split — audience-based, not network-zone

This commit is contained in:
2026-08-11 11:57:51 +00:00
parent 97fbbabb79
commit 05edddf996
+31 -19
View File
@@ -2,23 +2,42 @@
**Last updated:** 2026-08-11
## Split-Horizon DNS
## Domain Overview
The institute runs split-horizon DNS: internal and external services share
different domain namespaces to prevent internal service URLs from leaking
publicly.
The institute uses two primary domains for hosted services. Both are publicly
accessible — there is no split-horizon or network-zone separation between them.
The distinction is **audience-based**, determined per-service by the operator.
| Scope | Domain | Usage |
|-------|--------|-------|
| Internal | `pldyn.net` | Services accessible only inside the management subnet |
| External | `sundialer.net` | Services exposed to the public internet |
| Domain | Audience |
|--------|----------|
| `pldyn.net` | Operator and technical audience — dashboards, dev tools, infrastructure services |
| `sundialer.net` | Family-facing consumer services |
Domain assignment is not automatic. When deploying a new service, use judgement
based on the audience above. If the assignment is not obvious, ask the operator.
## Service Assignment Reference
Observable pattern from live Traefik configuration:
| Domain | Services |
|--------|----------|
| `sundialer.net` | audiolib/podcasts, boxoffice, dawarich, navidrome/music, oCIS, paperless-ngx |
| `pldyn.net` | beszel, bin, cdn, drawpile, gitea/vcs, immich/curator, lcarsdb, solidtime, traefik, vaultwarden, yaade, actual, omni-tools, daystrom-relay, pldyn.net (main site) |
### External Services (own domains — not subject to the split above)
- `sarimportauthority.org`
- `convectionand.coffee`
- `bluejeanblankie.com`
- `raccoonsoncaffeine.cool`
## Wildcard Patterns
| Scope | Pattern |
|-------|---------|
| Internal | `*.pldyn.net` |
| External | `*.sundialer.net` |
| Domain | Pattern |
|--------|---------|
| `pldyn.net` | `*.pldyn.net` |
| `sundialer.net` | `*.sundialer.net` |
## Certificate Issuance
@@ -29,10 +48,3 @@ publicly.
Traefik uses Cloudflare API credentials (stored as Swarm secrets / env vars,
not in documentation) to complete the DNS challenge and obtain Let's Encrypt
certificates for both domains.
## Notes
- DNS records for `*.pldyn.net` resolve to internal IPs; they are not
publicly routable.
- DNS records for `*.sundialer.net` resolve to the public-facing IP managed
by Unifi / Cloudflare.