watcher: notify NS query failure and recovery (closes #104)
check / check (push) Successful in 1m31s
check / check (push) Successful in 1m31s
LookupAllRecords now returns each nameserver's response, so the watcher saves its status: ok when it answered, NXDOMAIN and no records included, and error with the reason when it timed out, answered SERVFAIL or REFUSED, or could not be reached. A nameserver that starts failing sends NS Failure and one that answers again sends NS Recovery. A failing nameserver is left out of the record change and inconsistency comparisons. The resolver used to report REFUSED and network errors as an answer with no records; they are now errors. A lookup cut short by its context now returns an error instead of a failure of the nameserver it was querying. Model: opus-5-5
This commit was merged in pull request #175.
This commit is contained in:
@@ -71,18 +71,25 @@ rejected.
|
||||
did on the previous check (additions, removals, value changes).
|
||||
- **NS query failure**: A nameserver that previously responded
|
||||
becomes unreachable (timeout, SERVFAIL, REFUSED, network error).
|
||||
This is distinct from "responded with no records."
|
||||
This is distinct from "responded with no records": a nameserver
|
||||
that answers NXDOMAIN or with no records has responded. The alert
|
||||
is sent once, on the check where it starts failing. A failing
|
||||
nameserver gives no records, so it is not reported as a record
|
||||
change or compared for inconsistency. A nameserver that is already
|
||||
failing on the first check that sees it is recorded silently.
|
||||
- **NS recovery**: A previously-unreachable nameserver starts
|
||||
responding again.
|
||||
responding again. Its records are not compared with those from
|
||||
before it failed, so a change made while it was failing is not
|
||||
reported as a record change.
|
||||
- **Inconsistency detected**: Two nameservers return different record
|
||||
sets for the same hostname and did not already differ on the previous
|
||||
check. Every pair of nameservers is compared. The alert is sent once
|
||||
for each such pair, on the check where they start to disagree, and not
|
||||
again while they keep disagreeing, including after a restart. A
|
||||
nameserver that was not in the previous check (newly added, or back
|
||||
after dropping out) and answers differently is reported on the check
|
||||
where it appears. If a pair agrees again and later disagrees, the
|
||||
alert is sent again.
|
||||
after dropping out), or failed on it, and answers differently is
|
||||
reported on the check where it answers. If a pair agrees again and
|
||||
later disagrees, the alert is sent again.
|
||||
|
||||
### TCP Port Monitoring
|
||||
|
||||
@@ -458,10 +465,14 @@ not as a merged view, to enable inconsistency detection.
|
||||
The `status` field for each per-nameserver entry and certificate entry
|
||||
tracks reachability:
|
||||
|
||||
| Status | Meaning |
|
||||
|-------------|-------------------------------------------------|
|
||||
| `ok` | Query succeeded, records are current |
|
||||
| `error` | Query failed (timeout, SERVFAIL, network error) |
|
||||
| Status | Meaning |
|
||||
|-------------|------------------------------------------------------------|
|
||||
| `ok` | Query succeeded, records are current |
|
||||
| `error` | Query failed (timeout, SERVFAIL, REFUSED, network error) |
|
||||
|
||||
A nameserver that answers NXDOMAIN or with no records has status `ok` and
|
||||
empty `records`. A nameserver whose query failed has status `error`, empty
|
||||
`records`, and the reason in `error`.
|
||||
|
||||
---
|
||||
|
||||
|
||||
Reference in New Issue
Block a user