Files

51 lines
1.7 KiB
Markdown

# DNS
**Last updated:** 2026-08-11
## Domain Overview
The institute uses two primary domains for hosted services. Both are publicly
accessible — there is no split-horizon or network-zone separation between them.
The distinction is **audience-based**, determined per-service by the operator.
| Domain | Audience |
|--------|----------|
| `pldyn.net` | Operator and technical audience — dashboards, dev tools, infrastructure services |
| `sundialer.net` | Family-facing consumer services |
Domain assignment is not automatic. When deploying a new service, use judgement
based on the audience above. If the assignment is not obvious, ask the operator.
## Service Assignment Reference
Observable pattern from live Traefik configuration:
| Domain | Services |
|--------|----------|
| `sundialer.net` | audiolib/podcasts, boxoffice, dawarich, navidrome/music, oCIS, paperless-ngx |
| `pldyn.net` | beszel, bin, cdn, drawpile, gitea/vcs, immich/curator, lcarsdb, solidtime, traefik, vaultwarden, yaade, actual, omni-tools, daystrom-relay, pldyn.net (main site) |
### External Services (own domains — not subject to the split above)
- `sarimportauthority.org`
- `convectionand.coffee`
- `bluejeanblankie.com`
- `raccoonsoncaffeine.cool`
## Wildcard Patterns
| Domain | Pattern |
|--------|---------|
| `pldyn.net` | `*.pldyn.net` |
| `sundialer.net` | `*.sundialer.net` |
## Certificate Issuance
- **Provider:** Cloudflare (DNS challenge)
- **Managed by:** Traefik — cert issuance and renewal are automatic
- **Challenge method:** DNS-01 (no HTTP challenge port required)
Traefik uses Cloudflare API credentials (stored as Swarm secrets / env vars,
not in documentation) to complete the DNS challenge and obtain Let's Encrypt
certificates for both domains.