check-dns: failures in red, passes in green (terminal only; NO_COLOR respected)
1 files changed,  +12, -5
M scripts/check-dns.sh
+12, -5
 1@@ -76,9 +76,16 @@ spki_sha256() {
 2 }
 3 EMPTY_SHA256=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
 4 
 5+# Colour only on a terminal, and not with NO_COLOR set (no-color.org).
 6+if [ -t 1 ] && [ -z "${NO_COLOR:-}" ]; then
 7+  red=$'\e[31m' green=$'\e[32m' reset=$'\e[0m'
 8+else
 9+  red="" green="" reset=""
10+fi
11+
12 problems=0
13-problem() { echo "  ✗ $*"; problems=$((problems + 1)); }
14-ok() { echo "  ✓ $*"; }
15+problem() { echo "  ${red}✗ $*${reset}"; problems=$((problems + 1)); }
16+ok() { echo "  ${green}✓${reset} $*"; }
17 
18 # --- Expected --------------------------------------------------------------
19 
20@@ -98,7 +105,7 @@ addrs() { # host -> A/AAAA lines for name $2
21     [ -z "$suffix" ] || printf '*%s\tCNAME\t%s\n' "$suffix" "$cell"
22     hash="$(spki_sha256 "$cell")"
23     if [ "$hash" = "$EMPTY_SHA256" ]; then
24-      echo "check-dns: couldn't fetch $cell's certificate on :25; its TLSA isn't checked" >&2
25+      echo "${red}check-dns: couldn't fetch $cell's certificate on :25; its TLSA isn't checked${reset}" >&2
26       problems=$((problems + 1))
27     else
28       printf '_25._tcp.%s\tTLSA\t3 1 1 %s\n' "$cell" "$hash"
29@@ -202,8 +209,8 @@ done < <(managed | awk -F'\t' '$2 == "TLSA"')
30 
31 echo
32 if [ "$problems" = 0 ]; then
33-  echo "check-dns: $zone matches the fleet"
34+  echo "${green}check-dns: $zone matches the fleet${reset}"
35 else
36-  echo "check-dns: $problems discrepancies in $zone"
37+  echo "${red}check-dns: $problems discrepancies in $zone${reset}"
38   exit 1
39 fi