deploy(sovrn): cells' Stalwart domain is sovrn.internal; fleet.mailDomain is now zone (9cbbce8)
4 files changed,  +14, -14
M Justfile
+1, -1
1@@ -293,7 +293,7 @@ _dns SCRIPT:
2     set -euo pipefail
3     fleet="$(mktemp)"; trap 'rm -f "$fleet"' EXIT
4     nix eval --json --impure --expr \
5-      'let f = import ((builtins.getFlake (toString ./.)).inputs.sovrn + "/nix/fleet.nix"); in { inherit (f) mailDomain rootHost; }' \
6+      'let f = import ((builtins.getFlake (toString ./.)).inputs.sovrn + "/nix/fleet.nix"); in { inherit (f) zone rootHost; }' \
7       2>/dev/null >"$fleet"
8     scripts/{{ SCRIPT }}.sh hosts.json "$fleet"
9 
M flake.lock
+4, -4
 1@@ -290,11 +290,11 @@
 2         "nixpkgs": "nixpkgs_4"
 3       },
 4       "locked": {
 5-        "lastModified": 1791548302,
 6-        "narHash": "sha256-GzI9vwElgpsenB2qeJIriNoStzLXOMnPG+N3w5gAZgY=",
 7+        "lastModified": 1791615814,
 8+        "narHash": "sha256-5ZLdbrcAEb8t3gXsShC+oX6avY4G2c8597ybXoivA54=",
 9         "ref": "HEAD",
10-        "rev": "3b678042310e83ba5bbc89a8ac2caaaaa38485a5",
11-        "revCount": 203,
12+        "rev": "d1530622ac036c0837c41cae93c50504ddcfaf60",
13+        "revCount": 204,
14         "type": "git",
15         "url": "file:///home/btburke/projects/sovrn"
16       },
M scripts/check-dns.sh
+8, -8
 1@@ -17,15 +17,15 @@
 2 #     _25._tcp.<relay>          no TLSA        the backup MX fails open
 3 #                                              (bug 209274a): it must be a
 4 #                                              validated NXDOMAIN, not a record
 5-#   apex (sovrn's fleet.nix at the locked input: mailDomain, rootHost)
 6-#     <mailDomain>              A / AAAA       rootHost's addresses
 7-#     <mailDomain>              MX 10 rootHost
 8+#   apex (sovrn's fleet.nix at the locked input: zone, rootHost)
 9+#     <zone>                    A / AAAA       rootHost's addresses
10+#     <zone>                    MX 10 rootHost
11 #   SMTP2GO branded names (bug e76f226)
12-#     dkim.<mailDomain>         CNAME dkim.smtp2go.net
13-#     return.<mailDomain>       CNAME return.smtp2go.net
14+#     dkim.<zone>               CNAME dkim.smtp2go.net
15+#     return.<zone>             CNAME return.smtp2go.net
16 #
17 # Checked against:
18-#   marque   the zone record in the PDS (at.marque.dns/<mailDomain>), the
19+#   marque   the zone record in the PDS (at.marque.dns/<zone>), the
20 #            source of truth Marque serves from. Records at names nobody
21 #            manages are listed for information, not flagged.
22 #   NS       every authoritative nameserver, queried directly for each
23@@ -36,7 +36,7 @@
24 #            on anything that doesn't validate.
25 #
26 # Usage: check-dns.sh <hosts.json> <fleet.json>
27-#   fleet.json: {"mailDomain": ..., "rootHost": ...}
28+#   fleet.json: {"zone": ..., "rootHost": ...}
29 # With CHECK_DNS_STATE=<dir>, also leaves what it compared there for
30 # update-dns.sh: expected.tsv, absent.tsv, record.json (the getRecord
31 # response, with its CID) and marque.tsv (one normalised line per entry of
32@@ -54,7 +54,7 @@ for t in curl jq dig openssl; do
33   command -v "$t" >/dev/null || { echo "check-dns: $t not on PATH" >&2; exit 2; }
34 done
35 
36-zone="$(jq -r .mailDomain "$FLEET")"
37+zone="$(jq -r .zone "$FLEET")"
38 root_host="$(jq -r .rootHost "$FLEET")"
39 
40 # Records are tab-separated lines: name, type, value. Names are FQDNs without
M scripts/update-dns.sh
+1, -1
1@@ -50,7 +50,7 @@ if CHECK_DNS_STATE="$state" "$here/check-dns.sh" "$INVENTORY" "$FLEET"; then
2 fi
3 [ -s "$state/record.json" ] || { echo "update-dns: check-dns didn't get as far as the Marque record" >&2; exit 2; }
4 
5-zone="$(jq -r .mailDomain "$FLEET")"
6+zone="$(jq -r .zone "$FLEET")"
7 cid="$(jq -r .cid "$state/record.json")"
8 count="$(jq '.value.records | length' "$state/record.json")"
9 # marque.tsv must line up with the record's entries (a tab or newline inside