docs(infra): add DNS split-horizon topology
This commit is contained in:
@@ -0,0 +1,38 @@
|
||||
# DNS
|
||||
|
||||
**Last updated:** 2026-08-11
|
||||
|
||||
## Split-Horizon DNS
|
||||
|
||||
The institute runs split-horizon DNS: internal and external services share
|
||||
different domain namespaces to prevent internal service URLs from leaking
|
||||
publicly.
|
||||
|
||||
| Scope | Domain | Usage |
|
||||
|-------|--------|-------|
|
||||
| Internal | `pldyn.net` | Services accessible only inside the management subnet |
|
||||
| External | `sundialer.net` | Services exposed to the public internet |
|
||||
|
||||
## Wildcard Patterns
|
||||
|
||||
| Scope | Pattern |
|
||||
|-------|---------|
|
||||
| Internal | `*.pldyn.net` |
|
||||
| External | `*.sundialer.net` |
|
||||
|
||||
## Certificate Issuance
|
||||
|
||||
- **Provider:** Cloudflare (DNS challenge)
|
||||
- **Managed by:** Traefik — cert issuance and renewal are automatic
|
||||
- **Challenge method:** DNS-01 (no HTTP challenge port required)
|
||||
|
||||
Traefik uses Cloudflare API credentials (stored as Swarm secrets / env vars,
|
||||
not in documentation) to complete the DNS challenge and obtain Let's Encrypt
|
||||
certificates for both domains.
|
||||
|
||||
## Notes
|
||||
|
||||
- DNS records for `*.pldyn.net` resolve to internal IPs; they are not
|
||||
publicly routable.
|
||||
- DNS records for `*.sundialer.net` resolve to the public-facing IP managed
|
||||
by Unifi / Cloudflare.
|
||||
Reference in New Issue
Block a user