5 files changed,
+18,
-10
+1,
-1
1@@ -58,7 +58,7 @@ No provider firewall today. If one is added, every sovrn cell needs:
2 | TCP | 22 | any | SSH | servers `modules/base.nix` |
3 | TCP | 25 | any | MX 10 for the cell's domains | sovrn `nix/modules/roles/cell.nix` |
4 | TCP | 80 | any | ACME HTTP-01, redirects | sovrn `roles/cell-edge.nix` |
5-| TCP | 443 | any | sovrnd, PDS origins (`*.pds1.eu.sovrn.at`), on-demand TLS | sovrn `roles/cell-edge.nix` |
6+| TCP | 443 | any | sovrnd, PDS origins (`*.pds99.eu.sovrn.at` on mx99), on-demand TLS | sovrn `roles/cell-edge.nix` |
7 | TCP | 465, 587 | any | Submission (implicit TLS, STARTTLS) for users' mail clients | sovrn `roles/cell.nix` |
8 | TCP | 143, 993 | any | IMAP (STARTTLS, implicit TLS) | sovrn `roles/cell.nix` |
9 | TCP | 2525 | the relays only (`152.53.243.113`, `2a0a:4cc0:2000:84c4:c4a5:5fff:fe80:c760`) | Relay ingress: the backup relay re-delivers queued mail here, unauthenticated, so it must never be open to anyone else | sovrn `roles/cell.nix` (`sovrn.cell.relaySources`, from the inventory) |
+4,
-4
1@@ -290,11 +290,11 @@
2 "nixpkgs": "nixpkgs_4"
3 },
4 "locked": {
5- "lastModified": 1791615814,
6- "narHash": "sha256-5ZLdbrcAEb8t3gXsShC+oX6avY4G2c8597ybXoivA54=",
7+ "lastModified": 1791618093,
8+ "narHash": "sha256-/7P6azeOMg5Uz5Qd11Fz1n1gZvXeSeDgyo5Ng/pqnQo=",
9 "ref": "HEAD",
10- "rev": "d1530622ac036c0837c41cae93c50504ddcfaf60",
11- "revCount": 204,
12+ "rev": "321bb2c15e6b92f3b82fca06a186526651fc48ab",
13+ "revCount": 205,
14 "type": "git",
15 "url": "file:///home/btburke/projects/sovrn"
16 },
M
hive.nix
+1,
-1
1@@ -103,7 +103,7 @@ let
2 )
3 {
4 sovrn.fleet = (host.settings or { }).sovrn or { };
5- sovrn.cell.pdsOriginSuffix = host.pdsOriginSuffix or null;
6+ sovrn.cell.pdsAutoProvision = host.pdsAutoProvision or false;
7 # Only the inventory's relays may reach the relay ingress port.
8 sovrn.cell.relaySources = lib.concatMap hostAddresses (hostsWithRole "sovrn-relay");
9 }
+1,
-1
1@@ -33,7 +33,7 @@
2 },
3 "mx99.eu.sovrn.at": {
4 "stateVersion": "26.05",
5- "pdsOriginSuffix": ".pds1.eu.sovrn.at",
6+ "pdsAutoProvision": true,
7 "provider": "hetzner",
8 "system": "aarch64-linux",
9 "disk": "/dev/sda",
+11,
-3
1@@ -5,7 +5,9 @@
2 # Expected records, all derived (nothing is listed by hand):
3 # cells (hosts.json, role sovrn-cell)
4 # <cell> A / AAAA the host's ipv4 / ipv6
5-# *<pdsOriginSuffix> CNAME <cell> the cell's PDS wildcard
6+# *.pdsN.<rest> CNAME <cell> the PDS wildcard of a cell
7+# mxN.<rest> with pdsAutoProvision
8+# (named as sovrn derives it)
9 # _25._tcp.<cell> TLSA 3 1 1 SHA-256 of the SPKI the cell
10 # serves on :25 right now
11 # relay (hosts.json, role sovrn-relay, settings.sovrnRelay.hostname)
12@@ -111,8 +113,14 @@ addrs() { # host -> A/AAAA lines for name $2
13 {
14 for cell in $(jq -r 'to_entries[] | select(.value.roles | index("sovrn-cell")) | .key' "$INVENTORY"); do
15 addrs "$cell" "$cell"
16- suffix="$(jq -r --arg h "$cell" '.[$h].pdsOriginSuffix // empty' "$INVENTORY")"
17- [ -z "$suffix" ] || printf '*%s\tCNAME\t%s\n' "$suffix" "$cell"
18+ if [ "$(jq -r --arg h "$cell" '.[$h].pdsAutoProvision // false' "$INVENTORY")" = true ]; then
19+ if [[ $cell =~ ^mx([0-9]+)\.(.+)$ ]]; then
20+ printf '*.pds%s.%s\tCNAME\t%s\n' "${BASH_REMATCH[1]}" "${BASH_REMATCH[2]}" "$cell"
21+ else
22+ echo "${red}check-dns: $cell has pdsAutoProvision but isn't named mxN.<rest>${reset}" >&2
23+ problems=$((problems + 1))
24+ fi
25+ fi
26 hash="$(spki_sha256 "$cell")"
27 if [ "$hash" = "$EMPTY_SHA256" ]; then
28 echo "${red}check-dns: couldn't fetch $cell's certificate on :25; its TLSA isn't checked${reset}" >&2