check / check (push) Successful in 1m4s
LookupAllRecords now returns each nameserver's response, so the watcher saves its status: ok when it answered, NXDOMAIN and no records included, and error with the reason when it timed out, answered SERVFAIL or REFUSED, or could not be reached. A nameserver that starts failing sends NS Failure and one that answers again sends NS Recovery. A failing nameserver is left out of the record change and inconsistency comparisons. The resolver used to report REFUSED and network errors as an answer with no records; they are now errors. A lookup cut short by its context now returns an error instead of a failure of the nameserver it was querying. Model: opus-5-5
6.1 KiB
6.1 KiB
Workflow
- branch (from
next) - do the work in Next Step
- move Next Step to the top of Completed Steps
- move the top item of Future Steps into Next Step
- commit (
TODO.mdchanges in the same commit as the work) - push
- open a PR against
next
Status
pre-1.0. No git tags. Work lands on next by PR. Open work for 1.0 is tracked
on the 1.0 milestone: https://git.eeqj.de/sneak/dnswatcher/milestone/7
Next Step
nameserver IP address changes: #105
Completed Steps
- 2026-10-01: a nameserver that does not answer is saved as
errorwith the reason, and NS failure and NS recovery are notified (closes #104). - 2026-10-01:
TODO.mdbrought up to date: open issues listed by URL, every Completed Steps entry cut to at most two lines (closes #146). - 2026-10-01: wildcard CORS now applies only to the public routes, not to
/metrics, and allows only the methods they serve (closes #100). - 2026-10-01:
internal/stateandinternal/watcherno longer export test-only constructors: two moved toexport_test.go, one is deleted (closes #111). - 2026-10-01: notify shutdown tests use one timing constant per meaning, name the bound they check, and require the drain's debug line (closes #116).
- 2026-09-29: the entrypoint chowns the data directory to
dnswatcherand runs dnswatcher as that user, so a host bind mount needs no chown (closes #166). - 2026-09-29: the live-DNS test package is renamed
internal/livednstest;make lintfails when program code imports it (closes #164). - 2026-09-29:
.golangci.ymlre-fetched fromsneak/prompts, withgomodguard_v2and the orgdepguardtest-supportrule (closes #123). - 2026-09-29: watcher and resolver tests that look something up in DNS use the real resolver against live DNS servers (closes #159).
- 2026-09-28: the inconsistency alert is sent once, when two nameservers start to disagree; every pair of nameservers is compared (closes #158).
- 2026-09-28: DNS names in record values (CNAME, MX, SRV and NS targets) are lower-cased, so letter case alone is not a change (closes #157).
- 2026-09-28: lint and tests run on every build:
script/cibuildandscript/dockerpass--no-cache-filter=lint,builder(closes #115). - 2026-09-28: the server timeout test drives
Runand checks the timeouts on thehttp.Serverit serves (closes #120). - 2026-09-28: upaas deploy readiness: the image runs as user
dnswatcherwith aHEALTHCHECK; README "Running under upaas" (closes #147). - 2026-09-21: added behavioural tests for
internal/globals,internal/healthcheck, andinternal/logger(closes #110). - 2026-09-21:
go mod tidydropped the redundantgolang.org/x/sync// indirectline soscript/bootstrapleaves a clean tree (#132) - 2026-08-10: comment-only corrections to
script/bootstrap,script/cibuildandDockerfile.lint; no behaviour changed. - 2026-08-10: MIT
LICENSEadded at the repository root; the README's first line and License section name the licence. - 2026-08-10: policy scaffold present:
REPO_POLICIES.md,.editorconfig,.dockerignore, CI workflow,make fmt-check,make docker,make hooks. - 2026-08-10: Go's test cache disabled in
script/test(-count=1), so every run queries live DNS; a failed run is rerun with-v. - 2026-08-10: live-DNS tests made robust rather than gated (#93): a limit on concurrent lookups, retries, and a quorum across nameservers.
- 2026-08-10: all linting moved into Docker:
script/lintbuildsDockerfile.lint, and the rootDockerfilehas its own lint stage. - 2026-08-09: in-flight notification deliveries are drained at shutdown, bounded by the shutdown deadline (#106).
- 2026-08-09:
http.Serversets all four socket timeouts;WriteTimeoutstays above the 60s handler timeout (#99). - 2026-08-09:
SecurityHeaders()middleware sets HSTS, CSP and the other security headersREPO_POLICIES.mdrequires on every response. - 2026-08-07: golangci-lint bumped to v2.12.2 and
.golangci.ymlset to the org config; fixed the resultinggoconst,duplandlllfindings. - 2026-07-07 Adopted scripts-to-rule-them-all:
script/entrypoints, Makefile shims, README Entrypoints section - 2026-02-20: iterative DNS resolver implemented
- 2026-02-20: CI actions and go install refs pinned to commit SHAs; Gitea Actions workflow added
- 2026-02-20: watcher monitoring orchestrator merged to main (#8)
- 2026-02-20: DOMAINS/HOSTNAMES unified into single TARGETS config (#11)
- 2026-02-19: TCP port connectivity checker, made concurrent with port validation; gosec G704 SSRF findings fixed without suppression
- 2026-02-19: TLS certificate inspector with no-peer-certificates error path and IP SANs
- 2026-02-19: gosec SSRF and formatting fixes on main
- 2026-02-19: initial scaffold with per-nameserver DNS monitoring model
Future Steps
DNSWATCHER_SENTRY_DSNdoes nothing: #107- invalid DNS or TLS interval silently replaced by the default: #177
- rate limit on
/metricsBasic Auth: #101 - images report version
dev: #109 - trial run of the finished image: #149
- 1.0 readiness: run it with a real config and read the logs: #66
goimportsinmake fmt-check, Markdown formatting: #119- final state save at shutdown: #114
internal/notifyshutdown tests hang when a drain returns early: #176- README accuracy sweep: #108
- README sections required by policy: #173
script/install-precommitin a linked worktree: #129- fixed root server order: #138
- review toward 1.0: #144