watcher: follow a watched name's CNAME for port and TLS checks (closes #203)
check / check (push) Failing after 2m1s
check / check (push) Failing after 2m1s
When a watched name's nameservers answer with a CNAME and no address, the DNS check asks ResolveIPAddresses for the name, which looks it up again and follows the chain, and saves the addresses at its end in the hostname state as cnameAddresses. The port and TLS checks use them. Before, a CNAME into another zone got no port or TLS checks. A change in those addresses is notified as a CNAME address change. When following fails, or none of the name's nameservers answered, the addresses the last check saved are kept. The domain check now runs the hostname check for the apex instead of a copy of it. Model: opus-5-5
This commit is contained in:
@@ -121,12 +121,22 @@ notification endpoint set, changes show only on the dashboard; see
|
||||
failed on it, and answers differently is reported on the check where it
|
||||
answers. If a pair agrees again and later disagrees, the alert is sent
|
||||
again.
|
||||
- **CNAME address change**: For a name whose nameservers answer with a CNAME
|
||||
and no address, the addresses at the end of its CNAME chain differ from
|
||||
those of the previous check, including when there are none now. Nothing is
|
||||
sent when the previous check saved none, or when the previous addresses
|
||||
were kept because the chain could not be followed or none of the name's
|
||||
nameservers answered.
|
||||
|
||||
### TCP Port Monitoring
|
||||
|
||||
- For every configured domain and hostname, constructs a deduplicated list of
|
||||
all IPv4 and IPv6 addresses resolved via A, AAAA, and CNAME chain resolution
|
||||
across all authoritative nameservers.
|
||||
the IPv4 and IPv6 addresses in the A and AAAA records its authoritative
|
||||
nameservers returned. When they returned a CNAME and no address, the CNAME
|
||||
chain is followed and the addresses at its end are used, and a change in those
|
||||
is notified as a CNAME address change. When the chain cannot be followed, or
|
||||
none of the name's nameservers answered, the addresses the last check found at
|
||||
its end are used.
|
||||
- Checks TCP connectivity on ports **80** and **443** for each IP address.
|
||||
- Every **1 hour**, re-checks all ports.
|
||||
- Any change in port availability triggers a notification:
|
||||
@@ -173,6 +183,8 @@ includes:
|
||||
- **DNS NS changes**: Which domain, which nameservers were added/removed.
|
||||
- **NS address changes**: Which domain, which nameserver, its old and new
|
||||
addresses.
|
||||
- **CNAME address changes**: Which hostname, the old and new addresses at the
|
||||
end of its CNAME chain.
|
||||
- **NS query failures**: Which nameserver failed, error type (timeout, SERVFAIL,
|
||||
REFUSED, network error), which hostname/domain affected.
|
||||
- **NS recoveries**: Which nameserver recovered, which hostname/domain.
|
||||
@@ -389,8 +401,11 @@ This approach ensures:
|
||||
servers.
|
||||
- Visibility into the full delegation chain.
|
||||
|
||||
For hostname monitoring, the resolver follows CNAME chains (with a depth limit
|
||||
to prevent loops) before collecting terminal A/AAAA records.
|
||||
A watched name's records are stored as its nameservers return them, CNAME
|
||||
included. When they return a CNAME and no address, the CNAME chain is followed
|
||||
(with a depth limit to prevent loops) to the A and AAAA records at its end, and
|
||||
the port and TLS checks use those addresses. Nameservers' addresses are found
|
||||
the same way.
|
||||
|
||||
---
|
||||
|
||||
@@ -478,6 +493,12 @@ nameservers, has status `error`, empty `records`, and the reason in `error`.
|
||||
resolves to. A state file without it loads, and the next check fills it in
|
||||
without a notification.
|
||||
|
||||
`cnameAddresses` lists the sorted addresses at the end of a hostname's CNAME
|
||||
chain, found when its nameservers answered with a CNAME and no address, and kept
|
||||
from the previous check when the chain cannot be followed or none of the name's
|
||||
nameservers answered. It is left out otherwise. A state file without it loads,
|
||||
and the next check fills it in without a notification.
|
||||
|
||||
---
|
||||
|
||||
## Entrypoints
|
||||
@@ -617,7 +638,9 @@ docker run -d \
|
||||
completes.
|
||||
- Port and TLS checks always use freshly resolved IP addresses from the DNS
|
||||
phase that immediately precedes them — never stale IPs from a previous
|
||||
cycle.
|
||||
cycle, with one exception: when a name's CNAME chain cannot be followed,
|
||||
or none of the name's nameservers answered, the addresses the previous
|
||||
cycle found at the end of the chain are used.
|
||||
4. **On change detection**: Send notifications to all configured endpoints,
|
||||
update in-memory state, persist to disk.
|
||||
5. **Shutdown**: The watcher stops checking and saves the final state to disk,
|
||||
|
||||
Reference in New Issue
Block a user