watcher: follow a watched name's CNAME for port and TLS checks (closes #203)
check / check (push) Failing after 2m1s

When a watched name's nameservers answer with a CNAME and no address,
the DNS check asks ResolveIPAddresses for the name, which looks it up
again and follows the chain, and saves the addresses at its end in the
hostname state as cnameAddresses. The port and TLS checks use them.
Before, a CNAME into another zone got no port or TLS checks. A change
in those addresses is notified as a CNAME address change. When
following fails, or none of the name's nameservers answered, the
addresses the last check saved are kept. The domain check now runs the
hostname check for the apex instead of a copy of it.

Model: opus-5-5
This commit is contained in:
2026-10-02 00:42:18 +00:00
parent c9510a986c
commit dbd3343251
7 changed files with 351 additions and 29 deletions
+9
View File
@@ -57,6 +57,15 @@ func (w *Watcher) ResolveNameserverAddresses(
return w.resolveNameserverAddresses(ctx, nameservers, prev)
}
// ResolveCNAMEAddresses exports resolveCNAMEAddresses for testing.
func (w *Watcher) ResolveCNAMEAddresses(
ctx context.Context,
hostname string,
current, prev *state.HostnameState,
) {
w.resolveCNAMEAddresses(ctx, hostname, current, prev)
}
// DetectNSAddressChanges exports detectNSAddressChanges for testing.
func (w *Watcher) DetectNSAddressChanges(
ctx context.Context,