check / check (push) Successful in 1m4s
LookupAllRecords now returns each nameserver's response, so the watcher saves its status: ok when it answered, NXDOMAIN and no records included, and error with the reason when it timed out, answered SERVFAIL or REFUSED, or could not be reached. A nameserver that starts failing sends NS Failure and one that answers again sends NS Recovery. A failing nameserver is left out of the record change and inconsistency comparisons. The resolver used to report REFUSED and network errors as an answer with no records; they are now errors. A lookup cut short by its context now returns an error instead of a failure of the nameserver it was querying. Model: opus-5-5
63 lines
1.5 KiB
Go
63 lines
1.5 KiB
Go
// Package watcher provides the main monitoring orchestrator.
|
|
package watcher
|
|
|
|
import (
|
|
"context"
|
|
|
|
"sneak.berlin/go/dnswatcher/internal/portcheck"
|
|
"sneak.berlin/go/dnswatcher/internal/resolver"
|
|
"sneak.berlin/go/dnswatcher/internal/tlscheck"
|
|
)
|
|
|
|
// DNSResolver performs iterative DNS resolution.
|
|
type DNSResolver interface {
|
|
// LookupNS discovers authoritative nameservers for a domain.
|
|
LookupNS(
|
|
ctx context.Context,
|
|
domain string,
|
|
) ([]string, error)
|
|
|
|
// LookupAllRecords queries all record types for a hostname,
|
|
// returning each nameserver's response keyed by nameserver.
|
|
LookupAllRecords(
|
|
ctx context.Context,
|
|
hostname string,
|
|
) (map[string]*resolver.NameserverResponse, error)
|
|
|
|
// ResolveIPAddresses resolves a hostname to all IP addresses.
|
|
ResolveIPAddresses(
|
|
ctx context.Context,
|
|
hostname string,
|
|
) ([]string, error)
|
|
}
|
|
|
|
// PortChecker tests TCP port connectivity.
|
|
type PortChecker interface {
|
|
// CheckPort tests TCP connectivity to an address and port.
|
|
CheckPort(
|
|
ctx context.Context,
|
|
address string,
|
|
port int,
|
|
) (*portcheck.PortResult, error)
|
|
}
|
|
|
|
// TLSChecker inspects TLS certificates.
|
|
type TLSChecker interface {
|
|
// CheckCertificate connects via TLS and returns cert info.
|
|
CheckCertificate(
|
|
ctx context.Context,
|
|
ip string,
|
|
hostname string,
|
|
) (*tlscheck.CertificateInfo, error)
|
|
}
|
|
|
|
// Notifier delivers notifications to configured endpoints.
|
|
type Notifier interface {
|
|
// SendNotification sends a notification with the given
|
|
// details.
|
|
SendNotification(
|
|
ctx context.Context,
|
|
title, message, priority string,
|
|
)
|
|
}
|