2024-01-08 22:17:37 +00:00
|
|
|
{ config, dns, ... }:
|
2024-01-07 19:24:12 +00:00
|
|
|
with dns.lib.combinators;
|
2024-01-08 22:17:37 +00:00
|
|
|
let
|
2024-01-14 16:59:32 +00:00
|
|
|
inherit (config.lab.networking) publicIPv4 dmzServicesIPv6 dockerSwarmIPv6;
|
2024-01-08 22:17:37 +00:00
|
|
|
in
|
2024-01-07 19:24:12 +00:00
|
|
|
{
|
|
|
|
CAA = letsEncrypt "caa@kun.is";
|
|
|
|
|
|
|
|
SOA = {
|
|
|
|
nameServer = "ns1";
|
|
|
|
adminEmail = "webmaster@kun.is";
|
2024-01-17 22:04:27 +00:00
|
|
|
serial = 2024011401;
|
2024-01-07 19:24:12 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
NS = [
|
|
|
|
"ns1.kun.is."
|
|
|
|
"ns2.kun.is."
|
|
|
|
];
|
|
|
|
|
|
|
|
MX = [
|
|
|
|
(mx.mx 10 "mail.kun.is.")
|
|
|
|
];
|
|
|
|
|
|
|
|
subdomains = {
|
2024-01-14 16:59:32 +00:00
|
|
|
"*" = {
|
|
|
|
A = [ publicIPv4 ];
|
|
|
|
AAAA = [ dockerSwarmIPv6 ];
|
|
|
|
};
|
2024-01-14 14:20:32 +00:00
|
|
|
|
|
|
|
ns = {
|
|
|
|
A = [ publicIPv4 ];
|
|
|
|
AAAA = [ dmzServicesIPv6 ];
|
|
|
|
};
|
|
|
|
|
|
|
|
ns1 = {
|
|
|
|
A = [ publicIPv4 ];
|
|
|
|
AAAA = [ dmzServicesIPv6 ];
|
|
|
|
};
|
|
|
|
|
|
|
|
ns2 = {
|
|
|
|
A = [ publicIPv4 ];
|
|
|
|
AAAA = [ dmzServicesIPv6 ];
|
|
|
|
};
|
2024-01-14 17:38:04 +00:00
|
|
|
|
|
|
|
# Override because we don't support IPv6 for Git SSH.
|
|
|
|
git = {
|
|
|
|
A = [ publicIPv4 ];
|
|
|
|
AAAA = [ ];
|
2024-01-17 22:04:27 +00:00
|
|
|
};
|
|
|
|
|
2024-01-17 18:13:46 +00:00
|
|
|
# Override because we don't support IPv6 for KMS.
|
|
|
|
kms = {
|
|
|
|
A = [ publicIPv4 ];
|
|
|
|
AAAA = [ ];
|
2024-01-14 17:38:04 +00:00
|
|
|
};
|
2024-01-20 18:01:46 +00:00
|
|
|
|
|
|
|
# Override because wg is on opnsense so ipv6 differs from "dmzServicesIPv6"
|
|
|
|
wg = {
|
|
|
|
A = [ publicIPv4 ];
|
|
|
|
AAAA = [ "2a0d:6e00:1a77::1" ];
|
|
|
|
};
|
|
|
|
|
2024-01-07 19:24:12 +00:00
|
|
|
};
|
|
|
|
}
|