docs(infra): add DNS split-horizon topology

This commit is contained in:
2026-08-11 11:50:48 +00:00
parent 94137a2986
commit dd1e7acaf7
+38
View File
@@ -0,0 +1,38 @@
# DNS
**Last updated:** 2026-08-11
## Split-Horizon DNS
The institute runs split-horizon DNS: internal and external services share
different domain namespaces to prevent internal service URLs from leaking
publicly.
| Scope | Domain | Usage |
|-------|--------|-------|
| Internal | `pldyn.net` | Services accessible only inside the management subnet |
| External | `sundialer.net` | Services exposed to the public internet |
## Wildcard Patterns
| Scope | Pattern |
|-------|---------|
| Internal | `*.pldyn.net` |
| External | `*.sundialer.net` |
## Certificate Issuance
- **Provider:** Cloudflare (DNS challenge)
- **Managed by:** Traefik — cert issuance and renewal are automatic
- **Challenge method:** DNS-01 (no HTTP challenge port required)
Traefik uses Cloudflare API credentials (stored as Swarm secrets / env vars,
not in documentation) to complete the DNS challenge and obtain Let's Encrypt
certificates for both domains.
## Notes
- DNS records for `*.pldyn.net` resolve to internal IPs; they are not
publicly routable.
- DNS records for `*.sundialer.net` resolve to the public-facing IP managed
by Unifi / Cloudflare.