resolver, watcher: a domain's nameservers are only its own delegation (closes #222)
check / check (push) Successful in 1m20s
check / check (push) Successful in 1m20s
When a domain's parent zone's servers answer NXDOMAIN, LookupNS returns ErrNXDomain. The watcher then saves the domain with no nameservers and nxdomain set, shown on the dashboard and in /api/v1/status, asks for none of its records and removes those saved, so its old nameservers go in one NS Change. A domain with no delegation of its own gets an empty set and its records are still asked at the zone it is in. FindAuthoritativeNameservers moves to a parent name only on one of those two answers; when the servers do not answer, it returns the error. After an upgrade, a domain without its own delegation that was saved with its parent zone's nameservers gets one NS Change; the README says so. Model: opus-5-5
This commit is contained in:
@@ -73,9 +73,21 @@ notification endpoint set, changes show only on the dashboard; see
|
||||
to discover all authoritative nameservers (NS records) for each domain.
|
||||
- Queries **every** discovered authoritative nameserver independently.
|
||||
- Stores the domain's NS record set, as its parent zone's servers delegate it,
|
||||
and the IPv4 and IPv6 addresses each nameserver's name resolves to.
|
||||
and the IPv4 and IPv6 addresses each nameserver's name resolves to. The set is
|
||||
only ever the domain's own delegation. A domain whose parent zone's servers
|
||||
answer NXDOMAIN, that it does not exist, has no nameservers and is shown as
|
||||
not existing (see Web Dashboard and HTTP API). A domain that exists but has no
|
||||
delegation of its own, such as `octocat.github.io`, has no nameservers either.
|
||||
When the parent zone's servers do not answer, the check fails and the set from
|
||||
the previous check is kept.
|
||||
- Any change triggers a notification:
|
||||
- NS added to or removed from that set.
|
||||
- NS added to or removed from that set. A domain that had nameservers on the
|
||||
previous check and no longer exists gets one with all of them removed.
|
||||
After an upgrade, a domain with no delegation of its own, for which an
|
||||
earlier version saved its parent zone's nameservers, also gets one with
|
||||
all of them removed, on its first check. That one does not mean the domain
|
||||
stopped existing: it is not shown as not existing, and its records are
|
||||
still watched.
|
||||
- NS address change: a nameserver that stays in the set resolves to
|
||||
different addresses than on the previous check. A nameserver added or
|
||||
removed gets only the NS change notification. When the lookup of a
|
||||
@@ -87,7 +99,10 @@ notification endpoint set, changes show only on the dashboard; see
|
||||
records, stored per nameserver. Their changes are notified as a hostname's
|
||||
are, as a record change, NS query failure, NS recovery, inconsistency or CNAME
|
||||
address change, in a message that starts `Domain:` where a hostname's starts
|
||||
`Hostname:`.
|
||||
`Hostname:`. A domain with no delegation of its own has these records asked at
|
||||
the servers of the zone it is in, as a hostname has. A domain that does not
|
||||
exist has none: they are not asked for, and those saved by an earlier check
|
||||
are removed without a notification.
|
||||
|
||||
### DNS Hostname Monitoring (Subdomains)
|
||||
|
||||
@@ -95,7 +110,11 @@ notification endpoint set, changes show only on the dashboard; see
|
||||
via the Public Suffix List).
|
||||
- Every **1 hour** by default, performs a full iterative trace to discover the
|
||||
authoritative nameservers of the zone the hostname is in, which is not always
|
||||
its last two labels (a name under `co.uk`, or in a delegated subdomain).
|
||||
its last two labels (a name under `co.uk`, or in a delegated subdomain). The
|
||||
trace moves from a name to its parent only when the servers asked answer that
|
||||
the name has no delegation of its own, or does not exist. When they do not
|
||||
answer, the check fails and the hostname's records from the previous check are
|
||||
kept.
|
||||
- Queries **each** authoritative nameserver independently for **all** record
|
||||
types: A, AAAA, CNAME, MX, TXT, SRV, CAA, NS.
|
||||
- Each record type is a query of its own. When a nameserver answers some types
|
||||
@@ -260,8 +279,9 @@ dnswatcher includes an unauthenticated, read-only web dashboard at the root URL
|
||||
(`/`). It displays:
|
||||
|
||||
- **Summary counts** for monitored domains, hostnames, ports, and certificates.
|
||||
- **Domains** with their discovered nameservers, and each domain's own records
|
||||
per nameserver and status, shown as a hostname's are.
|
||||
- **Domains** with their discovered nameservers, or "does not exist" for a
|
||||
domain whose parent zone's servers answered NXDOMAIN, and each domain's own
|
||||
records per nameserver and status, shown as a hostname's are.
|
||||
- **Hostnames** with per-nameserver DNS records and status. For a nameserver
|
||||
whose query failed, the reason is shown in place of the records.
|
||||
- **Ports** with open/closed state and the domains and hostnames that resolve to
|
||||
@@ -298,9 +318,11 @@ In `/api/v1/status`, each nameserver entry and certificate entry whose `status`
|
||||
is `error` also has `error`, the reason, as in the state file (see State File
|
||||
Format). A domain's own records are in its entry in `domains`, under
|
||||
`recordsByNameserver`, in the form a hostname's entry in `hostnames` has them
|
||||
under `nameservers`; `hostnames` and `counts.hostnames` hold no domain. A port
|
||||
entry lists the domains that resolve to its address in `domains`, and the
|
||||
hostnames in `hostnames`.
|
||||
under `nameservers`; `hostnames` and `counts.hostnames` hold no domain. A domain
|
||||
entry's `nxdomain` is `true` when the domain's parent zone's servers answered
|
||||
NXDOMAIN, that it does not exist; its `nameservers` and `recordsByNameserver`
|
||||
are then empty. A port entry lists the domains that resolve to its address in
|
||||
`domains`, and the hostnames in `hostnames`.
|
||||
|
||||
`/metrics` is served only when `DNSWATCHER_METRICS_USERNAME` is set, behind
|
||||
Basic Auth. It has the Prometheus Go client's default metrics only (Go runtime,
|
||||
@@ -588,6 +610,11 @@ nothing for it. Both lists are left out when empty.
|
||||
resolves to. A state file without it loads, and the next check fills it in
|
||||
without a notification.
|
||||
|
||||
A domain entry has `"nxdomain": true` when the domain's parent zone's servers
|
||||
answered NXDOMAIN, that it does not exist. Its `nameservers` and
|
||||
`nameserverAddresses` are then empty, and `hostnames` holds no entry for it.
|
||||
`nxdomain` is left out when false.
|
||||
|
||||
`cnameAddresses` lists the sorted addresses at the end of the chain of every
|
||||
CNAME target a hostname's nameservers gave, found when they answered with a
|
||||
CNAME and no address; it is empty when they answered with an address. When a
|
||||
|
||||
Reference in New Issue
Block a user