watcher: follow a watched name's CNAME for port and TLS checks (closes #203)
check / check (push) Failing after 2m1s
check / check (push) Failing after 2m1s
When a watched name's nameservers answer with a CNAME and no address, the DNS check asks ResolveIPAddresses for the name, which looks it up again and follows the chain, and saves the addresses at its end in the hostname state as cnameAddresses. The port and TLS checks use them. Before, a CNAME into another zone got no port or TLS checks. A change in those addresses is notified as a CNAME address change. When following fails, or none of the name's nameservers answered, the addresses the last check saved are kept. The domain check now runs the hostname check for the apex instead of a copy of it. Model: opus-5-5
This commit is contained in:
@@ -315,7 +315,8 @@ func lookupNameservers(t *testing.T, domain string) []string {
|
||||
return nameservers
|
||||
}
|
||||
|
||||
// addresses returns the A and AAAA values saved for a hostname.
|
||||
// addresses returns the A and AAAA values saved for a hostname, and the
|
||||
// addresses saved at the end of its CNAME chain.
|
||||
func addresses(hs *state.HostnameState) []string {
|
||||
var ips []string
|
||||
|
||||
@@ -324,7 +325,7 @@ func addresses(hs *state.HostnameState) []string {
|
||||
ips = append(ips, nsState.Records["AAAA"]...)
|
||||
}
|
||||
|
||||
return ips
|
||||
return append(ips, hs.CNAMEAddresses...)
|
||||
}
|
||||
|
||||
// assertNotified checks that a notification with this title and
|
||||
|
||||
Reference in New Issue
Block a user