watcher: notify nameserver address changes (closes #105)
check / check (push) Failing after 2m14s
check / check (push) Failing after 2m14s
Each domain check now looks up the addresses every nameserver's name resolves to, with the resolver's ResolveIPAddresses, and saves them sorted in the domain's state. A nameserver that stays in the delegation and resolves to different addresses sends one NS Address Change notification naming the domain, the nameserver and the old and new addresses. Added or removed nameservers get only the NS change notification. A failed or empty lookup keeps the previous addresses, because the resolver returns no address without an error when every server it asks times out. State files without the field load, and the next check fills it in silently. Watcher tests that run domain checks use example.com, which has two nameservers, to stay within the per-attempt limit. Model: opus-5-5
This commit is contained in:
@@ -15,10 +15,13 @@ on the 1.0 milestone: https://git.eeqj.de/sneak/dnswatcher/milestone/7
|
||||
|
||||
# Next Step
|
||||
|
||||
nameserver IP address changes: https://git.eeqj.de/sneak/dnswatcher/issues/105
|
||||
`DNSWATCHER_SENTRY_DSN` does nothing:
|
||||
https://git.eeqj.de/sneak/dnswatcher/issues/107
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-01: each nameserver's addresses are saved with its domain, and a
|
||||
change while it stays in the delegation is notified (closes #105).
|
||||
- 2026-10-01: the client address from `X-Forwarded-For` is the last entry that
|
||||
is not a trusted proxy, not the first, which the client sets (closes #181).
|
||||
- 2026-10-01: a nameserver that does not answer is saved as `error` with the
|
||||
@@ -99,8 +102,6 @@ nameserver IP address changes: https://git.eeqj.de/sneak/dnswatcher/issues/105
|
||||
|
||||
# Future Steps
|
||||
|
||||
- `DNSWATCHER_SENTRY_DSN` does nothing:
|
||||
https://git.eeqj.de/sneak/dnswatcher/issues/107
|
||||
- trial run of the finished image:
|
||||
https://git.eeqj.de/sneak/dnswatcher/issues/149
|
||||
- 1.0 readiness: run it with a real config and read the logs:
|
||||
|
||||
Reference in New Issue
Block a user