watcher: follow a watched name's CNAME for port and TLS checks (closes #203)
check / check (push) Failing after 37s
check / check (push) Failing after 37s
When a watched name's nameservers answer with a CNAME and no address, the DNS check follows every CNAME target they gave with ResolveIPAddresses and saves the addresses found for all of them in the hostname state as cnameAddresses, so nameservers that disagree on the target do not change them from check to check. The port and TLS checks use them. A change in them is notified as a CNAME address change, also from or to none. A state file without the field loads them as not known (nil), so its first check sends nothing for them. When a target cannot be followed, or none of the name's nameservers answered, the last check's addresses are kept. The domain check now runs the hostname check for the apex instead of a copy of it. Model: opus-5-5
This commit is contained in:
@@ -19,6 +19,8 @@ trial run of the finished image: https://git.eeqj.de/sneak/dnswatcher/issues/149
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-02: a watched name whose nameservers answer with a CNAME and no
|
||||
address gets port and TLS checks at the end of its CNAME chain (closes #203).
|
||||
- 2026-10-02: the resolver tries root servers, and every other server list it
|
||||
walks, in a random order each time, not always from the top (closes #138).
|
||||
- 2026-10-02: a name listed more than once in `DNSWATCHER_TARGETS`, in any
|
||||
|
||||
Reference in New Issue
Block a user