docs(infra): add DNS split-horizon topology
This commit is contained in:
@@ -0,0 +1,38 @@
|
|||||||
|
# DNS
|
||||||
|
|
||||||
|
**Last updated:** 2026-08-11
|
||||||
|
|
||||||
|
## Split-Horizon DNS
|
||||||
|
|
||||||
|
The institute runs split-horizon DNS: internal and external services share
|
||||||
|
different domain namespaces to prevent internal service URLs from leaking
|
||||||
|
publicly.
|
||||||
|
|
||||||
|
| Scope | Domain | Usage |
|
||||||
|
|-------|--------|-------|
|
||||||
|
| Internal | `pldyn.net` | Services accessible only inside the management subnet |
|
||||||
|
| External | `sundialer.net` | Services exposed to the public internet |
|
||||||
|
|
||||||
|
## Wildcard Patterns
|
||||||
|
|
||||||
|
| Scope | Pattern |
|
||||||
|
|-------|---------|
|
||||||
|
| Internal | `*.pldyn.net` |
|
||||||
|
| External | `*.sundialer.net` |
|
||||||
|
|
||||||
|
## Certificate Issuance
|
||||||
|
|
||||||
|
- **Provider:** Cloudflare (DNS challenge)
|
||||||
|
- **Managed by:** Traefik — cert issuance and renewal are automatic
|
||||||
|
- **Challenge method:** DNS-01 (no HTTP challenge port required)
|
||||||
|
|
||||||
|
Traefik uses Cloudflare API credentials (stored as Swarm secrets / env vars,
|
||||||
|
not in documentation) to complete the DNS challenge and obtain Let's Encrypt
|
||||||
|
certificates for both domains.
|
||||||
|
|
||||||
|
## Notes
|
||||||
|
|
||||||
|
- DNS records for `*.pldyn.net` resolve to internal IPs; they are not
|
||||||
|
publicly routable.
|
||||||
|
- DNS records for `*.sundialer.net` resolve to the public-facing IP managed
|
||||||
|
by Unifi / Cloudflare.
|
||||||
Reference in New Issue
Block a user