watcher: follow a watched name's CNAME for port and TLS checks (closes #203)
check / check (push) Failing after 2m4s

When a watched name's nameservers answer with a CNAME and no address,
the DNS check asks ResolveIPAddresses for the name, which looks it up
again and follows the chain, and saves the addresses at its end in the
hostname state as cnameAddresses. The port and TLS checks use them. A
change in them is notified as a CNAME address change, also from or to
none. A state file without the field loads them as not known (nil), so
its first check sends nothing for them. When following fails, or none
of the name's nameservers answered, the last check's addresses are
kept. The domain check now runs the hostname check for the apex
instead of a copy of it.

Model: opus-5-5
This commit is contained in:
2026-10-02 01:35:53 +00:00
parent 82836b41fd
commit bb7d56cd9a
8 changed files with 489 additions and 31 deletions
+2
View File
@@ -19,6 +19,8 @@ trial run of the finished image: https://git.eeqj.de/sneak/dnswatcher/issues/149
# Completed Steps
- 2026-10-02: a watched name whose nameservers answer with a CNAME and no
address gets port and TLS checks at the end of its CNAME chain (closes #203).
- 2026-10-02: the resolver tries root servers, and every other server list it
walks, in a random order each time, not always from the top (closes #138).
- 2026-10-02: a name listed more than once in `DNSWATCHER_TARGETS`, in any