Files
dnswatcher/TODO.md
T
sneak 9077ec3582
check / check (push) Successful in 1m42s
docs: bring TODO.md up to date (closes #146)
Next Step and Future Steps now list the open issues by full URL, in the
order of the review on #144,
without DNSSEC (post-1.0) or issues waiting on the owner; two issues filed
since the review sit next to the entries they relate to. Shipped work, the
dropped domains and hostnames endpoints and the line about mocked resolver
tests are gone. Every Completed Steps entry is at most two lines; none was
dropped. Workflow now branches from `next` and opens PRs against it.
Wrapped by hand at 80 columns, since `make fmt` does not format Markdown
yet (#119). The old Next Step,
README sections required by policy, is not marked done: it is now
#173.

Model: opus-5-5
2026-10-01 18:27:55 +00:00

5.3 KiB

Workflow

  • branch (from next)
  • do the work in Next Step
  • move Next Step to the top of Completed Steps
  • move the top item of Future Steps into Next Step
  • commit (TODO.md changes in the same commit as the work)
  • push
  • open a PR against next

Status

pre-1.0. No git tags. Work lands on next by PR. Open work for 1.0 is tracked on the 1.0 milestone: https://git.eeqj.de/sneak/dnswatcher/milestone/7

Next Step

NS failure and NS recovery notifications: #104

Completed Steps

  • 2026-10-01: TODO.md brought up to date: open issues listed by URL, every Completed Steps entry cut to at most two lines (closes #146).
  • 2026-09-29: the live-DNS test package is renamed internal/livednstest; make lint fails when program code imports it (closes #164).
  • 2026-09-29: .golangci.yml re-fetched from sneak/prompts, with gomodguard_v2 and the org depguard test-support rule (closes #123).
  • 2026-09-29: watcher and resolver tests that look something up in DNS use the real resolver against live DNS servers (closes #159).
  • 2026-09-28: the inconsistency alert is sent once, when two nameservers start to disagree; every pair of nameservers is compared (closes #158).
  • 2026-09-28: DNS names in record values (CNAME, MX, SRV and NS targets) are lower-cased, so letter case alone is not a change (closes #157).
  • 2026-09-28: lint and tests run on every build: script/cibuild and script/docker pass --no-cache-filter=lint,builder (closes #115).
  • 2026-09-28: the server timeout test drives Run and checks the timeouts on the http.Server it serves (closes #120).
  • 2026-09-28: upaas deploy readiness: the image runs as user dnswatcher with a HEALTHCHECK; README "Running under upaas" (closes #147).
  • 2026-09-21: added behavioural tests for internal/globals, internal/healthcheck, and internal/logger (closes #110).
  • 2026-09-21: go mod tidy dropped the redundant golang.org/x/sync // indirect line so script/bootstrap leaves a clean tree (#132)
  • 2026-08-10: comment-only corrections to script/bootstrap, script/cibuild and Dockerfile.lint; no behaviour changed.
  • 2026-08-10: MIT LICENSE added at the repository root; the README's first line and License section name the licence.
  • 2026-08-10: policy scaffold present: REPO_POLICIES.md, .editorconfig, .dockerignore, CI workflow, make fmt-check, make docker, make hooks.
  • 2026-08-10: Go's test cache disabled in script/test (-count=1), so every run queries live DNS; a failed run is rerun with -v.
  • 2026-08-10: live-DNS tests made robust rather than gated (#93): a limit on concurrent lookups, retries, and a quorum across nameservers.
  • 2026-08-10: all linting moved into Docker: script/lint builds Dockerfile.lint, and the root Dockerfile has its own lint stage.
  • 2026-08-09: in-flight notification deliveries are drained at shutdown, bounded by the shutdown deadline (#106).
  • 2026-08-09: http.Server sets all four socket timeouts; WriteTimeout stays above the 60s handler timeout (#99).
  • 2026-08-09: SecurityHeaders() middleware sets HSTS, CSP and the other security headers REPO_POLICIES.md requires on every response.
  • 2026-08-07: golangci-lint bumped to v2.12.2 and .golangci.yml set to the org config; fixed the resulting goconst, dupl and lll findings.
  • 2026-07-07 Adopted scripts-to-rule-them-all: script/ entrypoints, Makefile shims, README Entrypoints section
  • 2026-02-20: iterative DNS resolver implemented
  • 2026-02-20: CI actions and go install refs pinned to commit SHAs; Gitea Actions workflow added
  • 2026-02-20: watcher monitoring orchestrator merged to main (#8)
  • 2026-02-20: DOMAINS/HOSTNAMES unified into single TARGETS config (#11)
  • 2026-02-19: TCP port connectivity checker, made concurrent with port validation; gosec G704 SSRF findings fixed without suppression
  • 2026-02-19: TLS certificate inspector with no-peer-certificates error path and IP SANs
  • 2026-02-19: gosec SSRF and formatting fixes on main
  • 2026-02-19: initial scaffold with per-nameserver DNS monitoring model

Future Steps

  • nameserver IP address changes: #105
  • DNSWATCHER_SENTRY_DSN does nothing: #107
  • CORS on /metrics: #100
  • rate limit on /metrics Basic Auth: #101
  • images report version dev: #109
  • trial run of the finished image: #149
  • goimports in make fmt-check, Markdown formatting: #119
  • final state save at shutdown: #114
  • test-only constructors in internal/state: #111
  • internal/notify shutdown tests: #116
  • internal/notify shutdown tests hang when a drain returns early: #176
  • README accuracy sweep: #108
  • README sections required by policy: #173
  • script/install-precommit in a linked worktree: #129