deploy(sovrn): mx99's PDS origins are *.pds99, derived from its MX name (6bb1d7e)
5 files changed,  +18, -10
M docs/runbooks/provider-firewalls.md
+1, -1
1@@ -58,7 +58,7 @@ No provider firewall today. If one is added, every sovrn cell needs:
2 | TCP | 22 | any | SSH | servers `modules/base.nix` |
3 | TCP | 25 | any | MX 10 for the cell's domains | sovrn `nix/modules/roles/cell.nix` |
4 | TCP | 80 | any | ACME HTTP-01, redirects | sovrn `roles/cell-edge.nix` |
5-| TCP | 443 | any | sovrnd, PDS origins (`*.pds1.eu.sovrn.at`), on-demand TLS | sovrn `roles/cell-edge.nix` |
6+| TCP | 443 | any | sovrnd, PDS origins (`*.pds99.eu.sovrn.at` on mx99), on-demand TLS | sovrn `roles/cell-edge.nix` |
7 | TCP | 465, 587 | any | Submission (implicit TLS, STARTTLS) for users' mail clients | sovrn `roles/cell.nix` |
8 | TCP | 143, 993 | any | IMAP (STARTTLS, implicit TLS) | sovrn `roles/cell.nix` |
9 | TCP | 2525 | the relays only (`152.53.243.113`, `2a0a:4cc0:2000:84c4:c4a5:5fff:fe80:c760`) | Relay ingress: the backup relay re-delivers queued mail here, unauthenticated, so it must never be open to anyone else | sovrn `roles/cell.nix` (`sovrn.cell.relaySources`, from the inventory) |
M flake.lock
+4, -4
 1@@ -290,11 +290,11 @@
 2         "nixpkgs": "nixpkgs_4"
 3       },
 4       "locked": {
 5-        "lastModified": 1791615814,
 6-        "narHash": "sha256-5ZLdbrcAEb8t3gXsShC+oX6avY4G2c8597ybXoivA54=",
 7+        "lastModified": 1791618093,
 8+        "narHash": "sha256-/7P6azeOMg5Uz5Qd11Fz1n1gZvXeSeDgyo5Ng/pqnQo=",
 9         "ref": "HEAD",
10-        "rev": "d1530622ac036c0837c41cae93c50504ddcfaf60",
11-        "revCount": 204,
12+        "rev": "321bb2c15e6b92f3b82fca06a186526651fc48ab",
13+        "revCount": 205,
14         "type": "git",
15         "url": "file:///home/btburke/projects/sovrn"
16       },
M hive.nix
+1, -1
1@@ -103,7 +103,7 @@ let
2       )
3       {
4         sovrn.fleet = (host.settings or { }).sovrn or { };
5-        sovrn.cell.pdsOriginSuffix = host.pdsOriginSuffix or null;
6+        sovrn.cell.pdsAutoProvision = host.pdsAutoProvision or false;
7         # Only the inventory's relays may reach the relay ingress port.
8         sovrn.cell.relaySources = lib.concatMap hostAddresses (hostsWithRole "sovrn-relay");
9       }
M hosts.json
+1, -1
1@@ -33,7 +33,7 @@
2   },
3   "mx99.eu.sovrn.at": {
4     "stateVersion": "26.05",
5-    "pdsOriginSuffix": ".pds1.eu.sovrn.at",
6+    "pdsAutoProvision": true,
7     "provider": "hetzner",
8     "system": "aarch64-linux",
9     "disk": "/dev/sda",
M scripts/check-dns.sh
+11, -3
 1@@ -5,7 +5,9 @@
 2 # Expected records, all derived (nothing is listed by hand):
 3 #   cells (hosts.json, role sovrn-cell)
 4 #     <cell>                    A / AAAA       the host's ipv4 / ipv6
 5-#     *<pdsOriginSuffix>        CNAME <cell>   the cell's PDS wildcard
 6+#     *.pdsN.<rest>             CNAME <cell>   the PDS wildcard of a cell
 7+#                                              mxN.<rest> with pdsAutoProvision
 8+#                                              (named as sovrn derives it)
 9 #     _25._tcp.<cell>           TLSA 3 1 1     SHA-256 of the SPKI the cell
10 #                                              serves on :25 right now
11 #   relay (hosts.json, role sovrn-relay, settings.sovrnRelay.hostname)
12@@ -111,8 +113,14 @@ addrs() { # host -> A/AAAA lines for name $2
13 {
14   for cell in $(jq -r 'to_entries[] | select(.value.roles | index("sovrn-cell")) | .key' "$INVENTORY"); do
15     addrs "$cell" "$cell"
16-    suffix="$(jq -r --arg h "$cell" '.[$h].pdsOriginSuffix // empty' "$INVENTORY")"
17-    [ -z "$suffix" ] || printf '*%s\tCNAME\t%s\n' "$suffix" "$cell"
18+    if [ "$(jq -r --arg h "$cell" '.[$h].pdsAutoProvision // false' "$INVENTORY")" = true ]; then
19+      if [[ $cell =~ ^mx([0-9]+)\.(.+)$ ]]; then
20+        printf '*.pds%s.%s\tCNAME\t%s\n' "${BASH_REMATCH[1]}" "${BASH_REMATCH[2]}" "$cell"
21+      else
22+        echo "${red}check-dns: $cell has pdsAutoProvision but isn't named mxN.<rest>${reset}" >&2
23+        problems=$((problems + 1))
24+      fi
25+    fi
26     hash="$(spki_sha256 "$cell")"
27     if [ "$hash" = "$EMPTY_SHA256" ]; then
28       echo "${red}check-dns: couldn't fetch $cell's certificate on :25; its TLSA isn't checked${reset}" >&2