watcher: notify NS query failure and recovery (closes #104)
check / check (push) Successful in 1m31s

LookupAllRecords now returns each nameserver's response, so the
watcher saves its status: ok when it answered, NXDOMAIN and no records
included, and error with the reason when it timed out, answered
SERVFAIL or REFUSED, or could not be reached. A nameserver that starts
failing sends NS Failure and one that answers again sends NS Recovery.
A failing nameserver is left out of the record change and
inconsistency comparisons. The resolver used to report REFUSED and
network errors as an answer with no records; they are now errors. A
lookup cut short by its context now returns an error instead of a
failure of the nameserver it was querying.

Model: opus-5-5
This commit was merged in pull request #175.
This commit is contained in:
2026-10-01 22:23:33 +02:00
parent fcd4f7e2c2
commit 8f11ef0038
11 changed files with 583 additions and 91 deletions
+20 -9
View File
@@ -71,18 +71,25 @@ rejected.
did on the previous check (additions, removals, value changes).
- **NS query failure**: A nameserver that previously responded
becomes unreachable (timeout, SERVFAIL, REFUSED, network error).
This is distinct from "responded with no records."
This is distinct from "responded with no records": a nameserver
that answers NXDOMAIN or with no records has responded. The alert
is sent once, on the check where it starts failing. A failing
nameserver gives no records, so it is not reported as a record
change or compared for inconsistency. A nameserver that is already
failing on the first check that sees it is recorded silently.
- **NS recovery**: A previously-unreachable nameserver starts
responding again.
responding again. Its records are not compared with those from
before it failed, so a change made while it was failing is not
reported as a record change.
- **Inconsistency detected**: Two nameservers return different record
sets for the same hostname and did not already differ on the previous
check. Every pair of nameservers is compared. The alert is sent once
for each such pair, on the check where they start to disagree, and not
again while they keep disagreeing, including after a restart. A
nameserver that was not in the previous check (newly added, or back
after dropping out) and answers differently is reported on the check
where it appears. If a pair agrees again and later disagrees, the
alert is sent again.
after dropping out), or failed on it, and answers differently is
reported on the check where it answers. If a pair agrees again and
later disagrees, the alert is sent again.
### TCP Port Monitoring
@@ -458,10 +465,14 @@ not as a merged view, to enable inconsistency detection.
The `status` field for each per-nameserver entry and certificate entry
tracks reachability:
| Status | Meaning |
|-------------|-------------------------------------------------|
| `ok` | Query succeeded, records are current |
| `error` | Query failed (timeout, SERVFAIL, network error) |
| Status | Meaning |
|-------------|------------------------------------------------------------|
| `ok` | Query succeeded, records are current |
| `error` | Query failed (timeout, SERVFAIL, REFUSED, network error) |
A nameserver that answers NXDOMAIN or with no records has status `ok` and
empty `records`. A nameserver whose query failed has status `error`, empty
`records`, and the reason in `error`.
---