# DNS **Last updated:** 2026-08-11 ## Domain Overview The institute uses two primary domains for hosted services. Both are publicly accessible — there is no split-horizon or network-zone separation between them. The distinction is **audience-based**, determined per-service by the operator. | Domain | Audience | |--------|----------| | `pldyn.net` | Operator and technical audience — dashboards, dev tools, infrastructure services | | `sundialer.net` | Family-facing consumer services | Domain assignment is not automatic. When deploying a new service, use judgement based on the audience above. If the assignment is not obvious, ask the operator. ## Service Assignment Reference Observable pattern from live Traefik configuration: | Domain | Services | |--------|----------| | `sundialer.net` | audiolib/podcasts, boxoffice, dawarich, navidrome/music, oCIS, paperless-ngx | | `pldyn.net` | beszel, bin, cdn, drawpile, gitea/vcs, immich/curator, lcarsdb, solidtime, traefik, vaultwarden, yaade, actual, omni-tools, daystrom-relay, pldyn.net (main site) | ### External Services (own domains — not subject to the split above) - `sarimportauthority.org` - `convectionand.coffee` - `bluejeanblankie.com` - `raccoonsoncaffeine.cool` ## Wildcard Patterns | Domain | Pattern | |--------|---------| | `pldyn.net` | `*.pldyn.net` | | `sundialer.net` | `*.sundialer.net` | ## Certificate Issuance - **Provider:** Cloudflare (DNS challenge) - **Managed by:** Traefik — cert issuance and renewal are automatic - **Challenge method:** DNS-01 (no HTTP challenge port required) Traefik uses Cloudflare API credentials (stored as Swarm secrets / env vars, not in documentation) to complete the DNS challenge and obtain Let's Encrypt certificates for both domains.