diff --git a/infrastructure/dns.md b/infrastructure/dns.md new file mode 100644 index 0000000..7a63145 --- /dev/null +++ b/infrastructure/dns.md @@ -0,0 +1,38 @@ +# DNS + +**Last updated:** 2026-08-11 + +## Split-Horizon DNS + +The institute runs split-horizon DNS: internal and external services share +different domain namespaces to prevent internal service URLs from leaking +publicly. + +| Scope | Domain | Usage | +|-------|--------|-------| +| Internal | `pldyn.net` | Services accessible only inside the management subnet | +| External | `sundialer.net` | Services exposed to the public internet | + +## Wildcard Patterns + +| Scope | Pattern | +|-------|---------| +| Internal | `*.pldyn.net` | +| External | `*.sundialer.net` | + +## Certificate Issuance + +- **Provider:** Cloudflare (DNS challenge) +- **Managed by:** Traefik — cert issuance and renewal are automatic +- **Challenge method:** DNS-01 (no HTTP challenge port required) + +Traefik uses Cloudflare API credentials (stored as Swarm secrets / env vars, +not in documentation) to complete the DNS challenge and obtain Let's Encrypt +certificates for both domains. + +## Notes + +- DNS records for `*.pldyn.net` resolve to internal IPs; they are not + publicly routable. +- DNS records for `*.sundialer.net` resolve to the public-facing IP managed + by Unifi / Cloudflare.