Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
55 changes: 53 additions & 2 deletions files/coredns/zones/noisebridge.io
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
$TTL 3600

noisebridge.io. IN SOA ns.noisebridge.net. hostmaster.noisebridge.io. (
2026033000 ; Serial
2026080400 ; Serial
3600 ; Refresh
300 ; Retry
604800 ; Expire
Expand All @@ -19,11 +19,38 @@ noisebridge.io. IN SOA ns.noisebridge.net. hostmaster.noisebridg
@ 300 IN AAAA 2602:ff06:725:5:dc::1337

; SPF
@ 86400 IN TXT "v=spf1 redirect=spf.noisebridge.net"
@ 300 IN TXT "v=spf1 mx -all"

; DMARC
_dmarc 300 IN TXT "v=DMARC1; p=none; rua=mailto:root@noisegarden.nexus;"
Comment thread
mcint marked this conversation as resolved.
Comment thread
mcint marked this conversation as resolved.

; DKIM
v1-rsa-20260706._domainkey IN TXT ( "v=DKIM1; k=rsa; "
"p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuje5z7r6FkT1XKMrq+0TeaH50XlZfqVuDv+2p7cjJDCuzeGtfcSa1Yf5mnQOxVaee/Dr0r+dlNB6YQLwaNRgBIX6+6qGRbIyegLXMoAX41SWm7+HoJdM/S+Gr/ITrFZOs3h0CxRTIvSVJjPj44OPp6sscjexG6RdQ4lai7tndesIPFITrwhQYR8Plht9DcB41"
"ygXHr/YpV9t4gYZyH10f2e5xnLvG7jhR5n7ugUu+EFeBVa6t294icpj/eioP6wgtPVDB5cfWHzk+jq1XmgQCYyDHORM8P+XKHfxN8V2WNUJ59IIPN8oUgIRDLOkPA4qHXEjclz2bLkoIL4jLB2ctQIDAQAB"
)
mail._domainkey IN CNAME mail._domainkey

; subdomains
barnyard 86400 IN NS brony.noisebridge.io.

;; Primary hosting servers.
; hetzner VPS
noisegarden-root IN A 204.168.192.161

; Services hosted on noisegarden-root
auth IN CNAME noisegarden-root
code IN CNAME noisegarden-root
git IN CNAME noisegarden-root
headscale IN CNAME noisegarden-root
mail IN CNAME noisegarden-root
vault IN CNAME noisegarden-root
; intent: test live deploy of https://github.com/noisebridge/noisebridge-wiki
; alpha: push whatever, whenever ; beta: focus on pre-deploy stability
wiki-alpha IN CNAME noisegarden-root
wiki-beta IN CNAME noisegarden-root
zulip IN CNAME noisegarden-root

Comment thread
mcint marked this conversation as resolved.
; aliases
blog 10800 IN CNAME blogs.vip.gandi.net.
brony 1800 IN A 199.241.139.224
Expand All @@ -35,3 +62,27 @@ share 1800 IN A 199.188.195.78
webmail 10800 IN CNAME webmail.gandi.net.
www 10800 IN CNAME m3.noisebridge.net.
zeppelin 1800 IN CNAME zeppelin.noisebridge.net.

; DNS-01 challenges enable automatic provisioning of certificates for services
; with no publically accessible HTTP-01 route, and are the ONLY way to get a
; wildcard certificate.
;
; Challenges here are answered by a self-hosted acme-dns on the NoiseGarden root
; cluster. To register a new subdomain, POST to /register from inside that
; cluster -- it has no public endpoint by design -- then point a CNAME at the
; fulldomain it returns.
;
; More info:
; * https://www.noisebridge.net/wiki/NoiseGarden
; * https://cert-manager.io/docs/configuration/acme/dns01/acme-dns/
; * infra/clusters/root/infra/acme-dns/README.md in the noisegarden repo
;
; The delegated subzone. Its NS host is the noisegarden-root record above, so no
; glue is needed; that address is also in the acme-dns config and the two must
; change together.
acme IN NS noisegarden-root.noisebridge.io.

; One CNAME covers every name in the zone, wildcard included. The target
; subdomain exists only in the acme-dns database and cannot be regenerated -- if
; that is lost, renewals fail until someone re-registers and edits this line.
_acme-challenge IN CNAME 03171cac-3a64-4105-a1a6-eacf70b4a076.acme.noisebridge.io.
38 changes: 23 additions & 15 deletions files/coredns/zones/noisebridge.net
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
$TTL 3600

noisebridge.net. IN SOA ns1.noisebridge.net. hostmaster.noisebridge.net. (
2026071700 ; Serial
2026073100 ; Serial
3600 ; Refresh
300 ; Retry
604800 ; Expire
Expand Down Expand Up @@ -65,6 +65,8 @@ m6 IN AAAA 2602:ff06:725:5:dc::196
; linode Seattle VM
m7 IN A 172.232.171.61
m7 IN AAAA 2600:3c0a::f03c:93ff:fe37:3d2f
; hetzner VPS
noisegarden-root IN A 204.168.192.161

status IN A 157.22.245.21

Expand Down Expand Up @@ -175,7 +177,10 @@ prometheus IN CNAME m5
test-safespace IN CNAME m5

; Services hosted on noisegarden-root (Hetzner VPS)
donate IN A 204.168.192.161
; The donate.* records below sit under a CNAME, which strictly speaking
; occludes them; CoreDNS serves them anyway (verified). Worth knowing if this
; zone ever moves to another server.
donate IN CNAME noisegarden-root

; donate.noisebridge.net email records (resend.com)
resend._domainkey.donate IN TXT "p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCoQWXGT4XLCErI5+ILqqMcSybWz1DxAqGyw9cxuaPN39YIyD6+SsvoP0p83iX3appGI4EXAVXe2YNPmNaa9UBnG7eio0tUe61L/J/82XEV/XbYTZpCGE5laIbQWZh77BBD9Ie6RpmYW2p1frnSUuz6BmnsT63fCToPfVU8K3jC/wIDAQAB"
Expand Down Expand Up @@ -219,23 +224,26 @@ upotagma IN A 107.170.233.49
upotagma IN AAAA 2604:a880:1:20:0:0:c3:a001


; DNS-01 challenges enable automatic provisioning of certificates to be used by intranet
; services on nodes that do not have a publically accessible route for an HTTP-01 challenge.
;
; DNS-01 challenges enable automatic provisioning of certificates for services
; with no publically accessible HTTP-01 route, and are the ONLY way to get a
; wildcard certificate.
;
; Challenges here are answered by a self-hosted acme-dns on the NoiseGarden root
; cluster. To register a new subdomain, POST to /register from inside that
; cluster -- it has no public endpoint by design -- then point a CNAME at the
; fulldomain it returns.
;
; More info:
; * https://www.noisebridge.net/wiki/NoiseGarden
; * https://cert-manager.io/docs/configuration/acme/dns01/acme-dns/
; * https://github.com/joohoi/acme-dns/
; * infra/clusters/root/infra/acme-dns/README.md in the noisegarden repo
;
; To register a new subdomain:
; * Using the following command and use the returned
; `curl -s -X POST https://auth.acme-dns.io/register | python -m json.tool`
; * Create a CNAME record pointing to the provided subdomain.
; * Use the provided credentials to self-provision a letsEncrypt cert.
;
; Note: We currently use auth.acme-dns.io but we can also self-host this service.
_acme-challenge IN CNAME f025e3fe-fbc8-4d3d-8d4f-cb8a2ac38f5e.auth.acme-dns.io.
; The target is in noisebridge.io rather than a subzone here: a CNAME may point
; anywhere, so this DNSSEC-signed zone needs no unsigned delegation of its own.
_acme-challenge IN CNAME 9d3537e8-f82c-490b-a915-3c1d3a497024.acme.noisebridge.io.

; Per-host accounts on the public auth.acme-dns.io, each held by the machine of
; that name. Repointing them from here would break their renewals.
_acme-challenge.colossus IN CNAME 16c8a8b7-44cc-4c18-8c43-0ae57d21b118.auth.acme-dns.io.
_acme-challenge.ducky IN CNAME 331d1498-d188-4fea-935c-7b2a225f684a.auth.acme-dns.io.
_acme-challenge.garden IN CNAME 89d749fd-a9c9-40f7-94e1-2c3cb32ec5c2.auth.acme-dns.io.
_acme-challenge.hw IN CNAME 2d7577da-b584-44d9-a247-789807870e7b.auth.acme-dns.io.
Loading