watcher: follow a watched name's CNAME for port and TLS checks (closes #203)
check / check (push) Successful in 1m53s

When a watched name's nameservers answer with a CNAME and no address,
the DNS check asks ResolveIPAddresses for the name, which looks it up
again and follows the chain, and saves the addresses at its end in the
hostname state as cnameAddresses. The port and TLS checks use them.
Before, only the A and AAAA records in the answers were used, so a
CNAME into another zone got no port or TLS checks. When following
fails, the addresses the last check saved are kept. The domain check
now runs the hostname check for the apex instead of a copy of it.

Model: opus-5-5
This commit is contained in:
2026-10-01 23:49:26 +00:00
parent 1f1640d4cd
commit 1b617847eb
7 changed files with 177 additions and 28 deletions
+9
View File
@@ -58,6 +58,15 @@ func (w *Watcher) ResolveNameserverAddresses(
return w.resolveNameserverAddresses(ctx, nameservers, prev)
}
// ResolveCNAMEAddresses exports resolveCNAMEAddresses for testing.
func (w *Watcher) ResolveCNAMEAddresses(
ctx context.Context,
hostname string,
current, prev *state.HostnameState,
) {
w.resolveCNAMEAddresses(ctx, hostname, current, prev)
}
// DetectNSAddressChanges exports detectNSAddressChanges for testing.
func (w *Watcher) DetectNSAddressChanges(
ctx context.Context,