diff --git a/files/coredns/zones/noisebridge.io b/files/coredns/zones/noisebridge.io index d1ede9c6..93919e3d 100644 --- a/files/coredns/zones/noisebridge.io +++ b/files/coredns/zones/noisebridge.io @@ -4,7 +4,7 @@ $TTL 3600 noisebridge.io. IN SOA ns.noisebridge.net. hostmaster.noisebridge.io. ( - 2026033000 ; Serial + 2026080400 ; Serial 3600 ; Refresh 300 ; Retry 604800 ; Expire @@ -19,11 +19,38 @@ noisebridge.io. IN SOA ns.noisebridge.net. hostmaster.noisebridg @ 300 IN AAAA 2602:ff06:725:5:dc::1337 ; SPF -@ 86400 IN TXT "v=spf1 redirect=spf.noisebridge.net" +@ 300 IN TXT "v=spf1 mx -all" + +; DMARC +_dmarc 300 IN TXT "v=DMARC1; p=none; rua=mailto:root@noisegarden.nexus;" + +; DKIM +v1-rsa-20260706._domainkey IN TXT ( "v=DKIM1; k=rsa; " + "p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuje5z7r6FkT1XKMrq+0TeaH50XlZfqVuDv+2p7cjJDCuzeGtfcSa1Yf5mnQOxVaee/Dr0r+dlNB6YQLwaNRgBIX6+6qGRbIyegLXMoAX41SWm7+HoJdM/S+Gr/ITrFZOs3h0CxRTIvSVJjPj44OPp6sscjexG6RdQ4lai7tndesIPFITrwhQYR8Plht9DcB41" + "ygXHr/YpV9t4gYZyH10f2e5xnLvG7jhR5n7ugUu+EFeBVa6t294icpj/eioP6wgtPVDB5cfWHzk+jq1XmgQCYyDHORM8P+XKHfxN8V2WNUJ59IIPN8oUgIRDLOkPA4qHXEjclz2bLkoIL4jLB2ctQIDAQAB" +) +mail._domainkey IN CNAME mail._domainkey ; subdomains barnyard 86400 IN NS brony.noisebridge.io. +;; Primary hosting servers. +; hetzner VPS +noisegarden-root IN A 204.168.192.161 + +; Services hosted on noisegarden-root +auth IN CNAME noisegarden-root +code IN CNAME noisegarden-root +git IN CNAME noisegarden-root +headscale IN CNAME noisegarden-root +mail IN CNAME noisegarden-root +vault IN CNAME noisegarden-root +; intent: test live deploy of https://github.com/noisebridge/noisebridge-wiki +; alpha: push whatever, whenever ; beta: focus on pre-deploy stability +wiki-alpha IN CNAME noisegarden-root +wiki-beta IN CNAME noisegarden-root +zulip IN CNAME noisegarden-root + ; aliases blog 10800 IN CNAME blogs.vip.gandi.net. brony 1800 IN A 199.241.139.224 @@ -35,3 +62,27 @@ share 1800 IN A 199.188.195.78 webmail 10800 IN CNAME webmail.gandi.net. www 10800 IN CNAME m3.noisebridge.net. zeppelin 1800 IN CNAME zeppelin.noisebridge.net. + +; DNS-01 challenges enable automatic provisioning of certificates for services +; with no publically accessible HTTP-01 route, and are the ONLY way to get a +; wildcard certificate. +; +; Challenges here are answered by a self-hosted acme-dns on the NoiseGarden root +; cluster. To register a new subdomain, POST to /register from inside that +; cluster -- it has no public endpoint by design -- then point a CNAME at the +; fulldomain it returns. +; +; More info: +; * https://www.noisebridge.net/wiki/NoiseGarden +; * https://cert-manager.io/docs/configuration/acme/dns01/acme-dns/ +; * infra/clusters/root/infra/acme-dns/README.md in the noisegarden repo +; +; The delegated subzone. Its NS host is the noisegarden-root record above, so no +; glue is needed; that address is also in the acme-dns config and the two must +; change together. +acme IN NS noisegarden-root.noisebridge.io. + +; One CNAME covers every name in the zone, wildcard included. The target +; subdomain exists only in the acme-dns database and cannot be regenerated -- if +; that is lost, renewals fail until someone re-registers and edits this line. +_acme-challenge IN CNAME 03171cac-3a64-4105-a1a6-eacf70b4a076.acme.noisebridge.io. diff --git a/files/coredns/zones/noisebridge.net b/files/coredns/zones/noisebridge.net index c9611823..43018ebe 100644 --- a/files/coredns/zones/noisebridge.net +++ b/files/coredns/zones/noisebridge.net @@ -4,7 +4,7 @@ $TTL 3600 noisebridge.net. IN SOA ns1.noisebridge.net. hostmaster.noisebridge.net. ( - 2026071700 ; Serial + 2026073100 ; Serial 3600 ; Refresh 300 ; Retry 604800 ; Expire @@ -65,6 +65,8 @@ m6 IN AAAA 2602:ff06:725:5:dc::196 ; linode Seattle VM m7 IN A 172.232.171.61 m7 IN AAAA 2600:3c0a::f03c:93ff:fe37:3d2f +; hetzner VPS +noisegarden-root IN A 204.168.192.161 status IN A 157.22.245.21 @@ -175,7 +177,10 @@ prometheus IN CNAME m5 test-safespace IN CNAME m5 ; Services hosted on noisegarden-root (Hetzner VPS) -donate IN A 204.168.192.161 +; The donate.* records below sit under a CNAME, which strictly speaking +; occludes them; CoreDNS serves them anyway (verified). Worth knowing if this +; zone ever moves to another server. +donate IN CNAME noisegarden-root ; donate.noisebridge.net email records (resend.com) resend._domainkey.donate IN TXT "p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCoQWXGT4XLCErI5+ILqqMcSybWz1DxAqGyw9cxuaPN39YIyD6+SsvoP0p83iX3appGI4EXAVXe2YNPmNaa9UBnG7eio0tUe61L/J/82XEV/XbYTZpCGE5laIbQWZh77BBD9Ie6RpmYW2p1frnSUuz6BmnsT63fCToPfVU8K3jC/wIDAQAB" @@ -219,23 +224,26 @@ upotagma IN A 107.170.233.49 upotagma IN AAAA 2604:a880:1:20:0:0:c3:a001 -; DNS-01 challenges enable automatic provisioning of certificates to be used by intranet -; services on nodes that do not have a publically accessible route for an HTTP-01 challenge. -; +; DNS-01 challenges enable automatic provisioning of certificates for services +; with no publically accessible HTTP-01 route, and are the ONLY way to get a +; wildcard certificate. +; +; Challenges here are answered by a self-hosted acme-dns on the NoiseGarden root +; cluster. To register a new subdomain, POST to /register from inside that +; cluster -- it has no public endpoint by design -- then point a CNAME at the +; fulldomain it returns. +; ; More info: ; * https://www.noisebridge.net/wiki/NoiseGarden ; * https://cert-manager.io/docs/configuration/acme/dns01/acme-dns/ -; * https://github.com/joohoi/acme-dns/ +; * infra/clusters/root/infra/acme-dns/README.md in the noisegarden repo ; -; To register a new subdomain: -; * Using the following command and use the returned -; `curl -s -X POST https://auth.acme-dns.io/register | python -m json.tool` -; * Create a CNAME record pointing to the provided subdomain. -; * Use the provided credentials to self-provision a letsEncrypt cert. -; -; Note: We currently use auth.acme-dns.io but we can also self-host this service. -_acme-challenge IN CNAME f025e3fe-fbc8-4d3d-8d4f-cb8a2ac38f5e.auth.acme-dns.io. +; The target is in noisebridge.io rather than a subzone here: a CNAME may point +; anywhere, so this DNSSEC-signed zone needs no unsigned delegation of its own. +_acme-challenge IN CNAME 9d3537e8-f82c-490b-a915-3c1d3a497024.acme.noisebridge.io. + +; Per-host accounts on the public auth.acme-dns.io, each held by the machine of +; that name. Repointing them from here would break their renewals. _acme-challenge.colossus IN CNAME 16c8a8b7-44cc-4c18-8c43-0ae57d21b118.auth.acme-dns.io. _acme-challenge.ducky IN CNAME 331d1498-d188-4fea-935c-7b2a225f684a.auth.acme-dns.io. -_acme-challenge.garden IN CNAME 89d749fd-a9c9-40f7-94e1-2c3cb32ec5c2.auth.acme-dns.io. _acme-challenge.hw IN CNAME 2d7577da-b584-44d9-a247-789807870e7b.auth.acme-dns.io.