watcher: follow a watched name's CNAME for port and TLS checks (closes #203)
check / check (push) Failing after 2m23s

When a watched name's nameservers answer with a CNAME and no address,
the DNS check asks ResolveIPAddresses for the name, which looks it up
again and follows the chain, and saves the addresses at its end in the
hostname state as cnameAddresses. The port and TLS checks use them.
Before, only the A and AAAA records in the answers were used, so a
CNAME into another zone got no port or TLS checks. When following
fails, the addresses the last check saved are kept. The domain check
now runs the hostname check for the apex instead of a copy of it.

Model: opus-5-5
This commit is contained in:
2026-10-01 23:47:49 +00:00
parent 11ce1b249b
commit 3472c8f4c1
7 changed files with 177 additions and 28 deletions
+14 -4
View File
@@ -125,8 +125,11 @@ notification endpoint set, changes show only on the dashboard; see
### TCP Port Monitoring
- For every configured domain and hostname, constructs a deduplicated list of
all IPv4 and IPv6 addresses resolved via A, AAAA, and CNAME chain resolution
across all authoritative nameservers.
the IPv4 and IPv6 addresses in the A and AAAA records its authoritative
nameservers returned. When they returned a CNAME and no address, the CNAME
chain is followed and the addresses at its end are used; a change in those
sends no notification of its own. When the chain cannot be followed, the
addresses the last check found at its end are used.
- Checks TCP connectivity on ports **80** and **443** for each IP address.
- Every **1 hour**, re-checks all ports.
- Any change in port availability triggers a notification:
@@ -389,8 +392,11 @@ This approach ensures:
servers.
- Visibility into the full delegation chain.
For hostname monitoring, the resolver follows CNAME chains (with a depth limit
to prevent loops) before collecting terminal A/AAAA records.
A watched name's records are stored as its nameservers return them, CNAME
included. When they return a CNAME and no address, the CNAME chain is followed
(with a depth limit to prevent loops) to the A and AAAA records at its end, and
the port and TLS checks use those addresses. Nameservers' addresses are found
the same way.
---
@@ -478,6 +484,10 @@ nameservers, has status `error`, empty `records`, and the reason in `error`.
resolves to. A state file without it loads, and the next check fills it in
without a notification.
`cnameAddresses` lists the sorted addresses at the end of a hostname's CNAME
chain, found when its nameservers answered with a CNAME and no address. It is
left out otherwise.
---
## Entrypoints