watcher: follow a watched name's CNAME for port and TLS checks (closes #203)
check / check (push) Failing after 2m1s

When a watched name's nameservers answer with a CNAME and no address,
the DNS check asks ResolveIPAddresses for the name, which looks it up
again and follows the chain, and saves the addresses at its end in the
hostname state as cnameAddresses. The port and TLS checks use them.
Before, a CNAME into another zone got no port or TLS checks. A change
in those addresses is notified as a CNAME address change. When
following fails, or none of the name's nameservers answered, the
addresses the last check saved are kept. The domain check now runs the
hostname check for the apex instead of a copy of it.

Model: opus-5-5
This commit is contained in:
2026-10-02 00:42:18 +00:00
parent c9510a986c
commit dbd3343251
7 changed files with 351 additions and 29 deletions
+28 -5
View File
@@ -121,12 +121,22 @@ notification endpoint set, changes show only on the dashboard; see
failed on it, and answers differently is reported on the check where it
answers. If a pair agrees again and later disagrees, the alert is sent
again.
- **CNAME address change**: For a name whose nameservers answer with a CNAME
and no address, the addresses at the end of its CNAME chain differ from
those of the previous check, including when there are none now. Nothing is
sent when the previous check saved none, or when the previous addresses
were kept because the chain could not be followed or none of the name's
nameservers answered.
### TCP Port Monitoring
- For every configured domain and hostname, constructs a deduplicated list of
all IPv4 and IPv6 addresses resolved via A, AAAA, and CNAME chain resolution
across all authoritative nameservers.
the IPv4 and IPv6 addresses in the A and AAAA records its authoritative
nameservers returned. When they returned a CNAME and no address, the CNAME
chain is followed and the addresses at its end are used, and a change in those
is notified as a CNAME address change. When the chain cannot be followed, or
none of the name's nameservers answered, the addresses the last check found at
its end are used.
- Checks TCP connectivity on ports **80** and **443** for each IP address.
- Every **1 hour**, re-checks all ports.
- Any change in port availability triggers a notification:
@@ -173,6 +183,8 @@ includes:
- **DNS NS changes**: Which domain, which nameservers were added/removed.
- **NS address changes**: Which domain, which nameserver, its old and new
addresses.
- **CNAME address changes**: Which hostname, the old and new addresses at the
end of its CNAME chain.
- **NS query failures**: Which nameserver failed, error type (timeout, SERVFAIL,
REFUSED, network error), which hostname/domain affected.
- **NS recoveries**: Which nameserver recovered, which hostname/domain.
@@ -389,8 +401,11 @@ This approach ensures:
servers.
- Visibility into the full delegation chain.
For hostname monitoring, the resolver follows CNAME chains (with a depth limit
to prevent loops) before collecting terminal A/AAAA records.
A watched name's records are stored as its nameservers return them, CNAME
included. When they return a CNAME and no address, the CNAME chain is followed
(with a depth limit to prevent loops) to the A and AAAA records at its end, and
the port and TLS checks use those addresses. Nameservers' addresses are found
the same way.
---
@@ -478,6 +493,12 @@ nameservers, has status `error`, empty `records`, and the reason in `error`.
resolves to. A state file without it loads, and the next check fills it in
without a notification.
`cnameAddresses` lists the sorted addresses at the end of a hostname's CNAME
chain, found when its nameservers answered with a CNAME and no address, and kept
from the previous check when the chain cannot be followed or none of the name's
nameservers answered. It is left out otherwise. A state file without it loads,
and the next check fills it in without a notification.
---
## Entrypoints
@@ -617,7 +638,9 @@ docker run -d \
completes.
- Port and TLS checks always use freshly resolved IP addresses from the DNS
phase that immediately precedes them — never stale IPs from a previous
cycle.
cycle, with one exception: when a name's CNAME chain cannot be followed,
or none of the name's nameservers answered, the addresses the previous
cycle found at the end of the chain are used.
4. **On change detection**: Send notifications to all configured endpoints,
update in-memory state, persist to disk.
5. **Shutdown**: The watcher stops checking and saves the final state to disk,