diff --git a/.env b/.env index dbd6669..94e3e7a 100644 --- a/.env +++ b/.env @@ -7,5 +7,5 @@ DOTENV_KEYS_LOADED=1 DOTENV_PUBLIC_KEY="020c13c2e7b3510fe62231d2968375be7f35972e0f8c7a6691110133f72274a2b5" # .env -CLOUDFLARE_API_TOKEN="encrypted:BKv61BfHcaxS9Z9RnXsXP9YgcugK4Ai1UyYk/tlSOyECeQ1qwFsLvltrxbGOo5lqQ/jzma/Q5o3MgznaWx2/5joeJTAqI+wJkkVfu89bqv1LQzoS0g+MbKiTWDNr0WsQEpxDal+7EMIk9w9vCLc1IQgUYC2Z7cbNDE+GTLizf94JdPqSDTNW2Co=" -CLOUDFLARE_TOKEN="encrypted:BKv61BfHcaxS9Z9RnXsXP9YgcugK4Ai1UyYk/tlSOyECeQ1qwFsLvltrxbGOo5lqQ/jzma/Q5o3MgznaWx2/5joeJTAqI+wJkkVfu89bqv1LQzoS0g+MbKiTWDNr0WsQEpxDal+7EMIk9w9vCLc1IQgUYC2Z7cbNDE+GTLizf94JdPqSDTNW2Co=" +CLOUDFLARE_TOKEN="encrypted:BOjtLj9PLOmryNosK1a/N/4IJ/bU7QRytKSEn6dmwh9xQKsezo4peUjp5BZVQz02DsPcjbFN1AARVDBUfuOxAuJiLrGhgVBbyaZ9RzeqEtItjFEwboCmGDa/2fks4Fdn6mOFGgdsTYPOp32xmEPnomZ6HaDIaTKrZPzcktnptIDyFdhlZ4LwCsE=" +CLOUDFLARE_API_TOKEN="$CLOUDFLARE_TOKEN" diff --git a/Pipfile b/Pipfile index a798b27..6af0126 100644 --- a/Pipfile +++ b/Pipfile @@ -13,5 +13,6 @@ octodns-cloudflare = "*" python_version = "3.12" [scripts] +dns-export = "octodns-dump --config-file=octodns-config.yml --output-dir dns" dns-dryrun = "octodns-sync --config-file=./dns/octodns-config.yml" dns-apply = "octodns-sync --config-file=./dns/octodns-config.yml --doit" diff --git a/deno.lock b/deno.lock index 797cd50..bc8d491 100644 --- a/deno.lock +++ b/deno.lock @@ -4,7 +4,7 @@ "jsr:@std/bytes@^1.0.2": "1.0.2", "jsr:@std/path@*": "1.0.3", "jsr:@std/streams@*": "1.0.3", - "npm:@dotenvx/dotenvx@^1.32.1": "1.32.1_picomatch@4.0.2", + "npm:@dotenvx/dotenvx@^1.34.0": "1.34.0_picomatch@4.0.2", "npm:@types/node@*": "18.16.19", "npm:commander@*": "12.1.0", "npm:execa@*": "9.3.1", @@ -25,8 +25,8 @@ } }, "npm": { - "@dotenvx/dotenvx@1.32.1_picomatch@4.0.2": { - "integrity": "sha512-xuTL8XLFkC0B0xHQzBPROY6WBwb9MA0LYBVNIinJ0VD9+gHOIuSyQut0RyDA7tmqxvZQ3C4roZ0HaWvHgX3sZQ==", + "@dotenvx/dotenvx@1.34.0_picomatch@4.0.2": { + "integrity": "sha512-+Dp/xaI3IZ4eKv+b2vg4V89VnqLKbmJ7UZ7unnZxMu9SNLOSc2jYaXey1YHCJM+67T0pOr2Gbej3TewnuoqTWQ==", "dependencies": [ "commander@11.1.0", "dotenv", @@ -39,23 +39,23 @@ "which@4.0.0" ] }, - "@ecies/ciphers@0.2.2_@noble+ciphers@1.2.0": { + "@ecies/ciphers@0.2.2_@noble+ciphers@1.2.1": { "integrity": "sha512-ylfGR7PyTd+Rm2PqQowG08BCKA22QuX8NzrL+LxAAvazN10DMwdJ2fWwAzRj05FI/M8vNFGm3cv9Wq/GFWCBLg==", "dependencies": [ "@noble/ciphers" ] }, - "@noble/ciphers@1.2.0": { - "integrity": "sha512-YGdEUzYEd+82jeaVbSKKVp1jFZb8LwaNMIIzHFkihGvYdd/KKAr7KaJHdEdSYGredE3ssSravXIa0Jxg28Sv5w==" + "@noble/ciphers@1.2.1": { + "integrity": "sha512-rONPWMC7PeExE077uLE4oqWrZ1IvAfz3oH9LibVAcVCopJiA9R62uavnbEzdkVmJYI6M6Zgkbeb07+tWjlq2XA==" }, - "@noble/curves@1.8.0": { - "integrity": "sha512-j84kjAbzEnQHaSIhRPUmB3/eVXu2k3dKPl2LOrR8fSOIL+89U+7lV117EWHtq/GHM3ReGHM46iRBdZfpc4HRUQ==", + "@noble/curves@1.8.1": { + "integrity": "sha512-warwspo+UYUPep0Q+vtdVB4Ugn8GGQj8iyB3gnRWsztmUHTI3S1nhdiWNsPUGL0vud7JlRRk1XEu7Lq1KGTnMQ==", "dependencies": [ "@noble/hashes" ] }, - "@noble/hashes@1.7.0": { - "integrity": "sha512-HXydb0DgzTpDPwbVeDGCG1gIu7X6+AuU6Zl6av/E/KG8LMsvPntvq+w17CHRpKBmN6Ybdrt1eP3k4cj8DJa78w==" + "@noble/hashes@1.7.1": { + "integrity": "sha512-B8XBPsn4vT/KJAGqDzbwztd+6Yte3P4V7iafm24bxgDe/mlRuK6xmWPuCNrKt2vDafZ8MfJLlchDG/vYafQEjQ==" }, "@sec-ant/readable-stream@0.4.1": { "integrity": "sha512-831qok9r2t8AlxLko40y2ebgSDhenenCatLVeW/uBtnHPyhHOvG0C7TvfgecV+wHzIm5KUICgzmVpWS+IMEAeg==" @@ -83,7 +83,7 @@ "dotenv@16.4.7": { "integrity": "sha512-47qPchRCykZC03FhkYAhrvwU4xDBFIj1QPqaarj6mdM/hgUzfPHcpkHJOn3mJAufFeeAxAzeGsr5X0M4k6fLZQ==" }, - "eciesjs@0.4.13_@noble+ciphers@1.2.0": { + "eciesjs@0.4.13_@noble+ciphers@1.2.1": { "integrity": "sha512-zBdtR4K+wbj10bWPpIOF9DW+eFYQu8miU5ypunh0t4Bvt83ZPlEWgT5Dq/0G6uwEXumZKjfb5BZxYUZQ2Hzn/Q==", "dependencies": [ "@ecies/ciphers", @@ -123,8 +123,8 @@ "yoctocolors" ] }, - "fdir@6.4.2_picomatch@4.0.2": { - "integrity": "sha512-KnhMXsKSPZlAhp7+IjUkRZKPb4fUyccpDrdFXbi4QL1qkmFh9kVY09Yox+n4MaOb3lHZ1Tv829C3oaaXoMYPDQ==", + "fdir@6.4.3_picomatch@4.0.2": { + "integrity": "sha512-PMXmW2y1hDDfTSRc9gaXIuCCRpuoz3Kaz8cUelp3smouvfT632ozg2vrT6lJsHKKOF59YLbOGfAWGUcKEfRMQw==", "dependencies": [ "picomatch" ] @@ -270,7 +270,7 @@ ], "packageJson": { "dependencies": [ - "npm:@dotenvx/dotenvx@^1.32.1" + "npm:@dotenvx/dotenvx@^1.34.0" ] } } diff --git a/dns/andreijiroh.dev.yaml b/dns/andreijiroh.dev.yaml index ff6ad38..436387a 100644 --- a/dns/andreijiroh.dev.yaml +++ b/dns/andreijiroh.dev.yaml @@ -59,21 +59,6 @@ ttl: 300 type: A value: 127.0.0.1 -'*.stellapent.tailnet': -- ttl: 300 - type: A - value: 100.87.227.94 -- ttl: 300 - type: AAAA - value: fd7a:115c:a1e0::a401:e35e -'*.wplabs': - octodns: - cloudflare: - auto-ttl: true - comment: tailnet-only WordPress lab - ttl: 300 - type: CNAME - value: wp.stellapent.tailnet.andreijiroh.dev. _acme-challenge.api: octodns: cloudflare: @@ -252,13 +237,25 @@ status: ttl: 300 type: CNAME value: andreijiroh-dev.github.io. -stellapent.tailnet: -- ttl: 300 - type: A - value: 100.87.227.94 -- ttl: 300 - type: AAAA - value: fd7a:115c:a1e0::a401:e35e +tailnet: +- octodns: + cloudflare: + auto-ttl: true + ttl: 300 + type: DS + value: + algorithm: 13 + digest: CC4238C1416F65932CE32BA56214DE0FD888CBDD042E881ED367EF3BC1C5E52C + digest_type: 2 + key_tag: 64753 +- octodns: + cloudflare: + auto-ttl: true + ttl: 300 + type: NS + values: + - ns1.desec.io. + - ns2.desec.org. tommy2heliohost._domainkey: octodns: cloudflare: @@ -305,14 +302,6 @@ wikilab: ttl: 300 type: CNAME value: nyc.domcloud.co. -wplabs: - octodns: - cloudflare: - auto-ttl: true - comment: tailnet-only WordPress lab - ttl: 300 - type: CNAME - value: wp.stellapent.tailnet.andreijiroh.dev. www: octodns: cloudflare: diff --git a/dns/andreijiroh.is-a.dev.yaml b/dns/andreijiroh.is-a.dev.yaml new file mode 100644 index 0000000..ea3f091 --- /dev/null +++ b/dns/andreijiroh.is-a.dev.yaml @@ -0,0 +1,31 @@ +--- +? '' +: octodns: + cloudflare: + auto-ttl: true + proxied: true + ttl: 300 + type: ALIAS + value: ajhalili2006.pages.dev. +_discord: + octodns: + cloudflare: + auto-ttl: true + comment: Discord domain verification + ttl: 300 + type: TXT + value: dh=3e418355487305cc4560b0611ba783271ccc066d +git.infraops: + octodns: + cloudflare: + auto-ttl: true + ttl: 300 + type: A + value: 69.30.249.53 +uptimekuma: + octodns: + cloudflare: + auto-ttl: true + ttl: 300 + type: A + value: 69.30.249.53 diff --git a/octodns-config.yml b/octodns-config.yml index 6031f04..9e28d13 100644 --- a/octodns-config.yml +++ b/octodns-config.yml @@ -13,15 +13,18 @@ zones: andreijiroh.dev.: sources: [config] targets: [cf] - andreijiroh.xyz.: + andreijiroh.is-a.dev.: sources: [config] targets: [cf] + #andreijiroh.xyz.: + # sources: [config] + # targets: [cf] andreijiroh.eu.org.: sources: [config] targets: [cf] - andreijiroh.uk.eu.org.: - sources: [config] - targets: [cf] + #andreijiroh.uk.eu.org.: + # sources: [config] + # targets: [cf] andreijiroh.pp.ua.: sources: [config] targets: [cf] \ No newline at end of file diff --git a/package-lock.json b/package-lock.json index f4fd089..bc0d812 100644 --- a/package-lock.json +++ b/package-lock.json @@ -5,13 +5,13 @@ "packages": { "": { "dependencies": { - "@dotenvx/dotenvx": "^1.32.1" + "@dotenvx/dotenvx": "^1.34.0" } }, "node_modules/@dotenvx/dotenvx": { - "version": "1.32.1", - "resolved": "https://registry.npmjs.org/@dotenvx/dotenvx/-/dotenvx-1.32.1.tgz", - "integrity": "sha512-xuTL8XLFkC0B0xHQzBPROY6WBwb9MA0LYBVNIinJ0VD9+gHOIuSyQut0RyDA7tmqxvZQ3C4roZ0HaWvHgX3sZQ==", + "version": "1.34.0", + "resolved": "https://registry.npmjs.org/@dotenvx/dotenvx/-/dotenvx-1.34.0.tgz", + "integrity": "sha512-+Dp/xaI3IZ4eKv+b2vg4V89VnqLKbmJ7UZ7unnZxMu9SNLOSc2jYaXey1YHCJM+67T0pOr2Gbej3TewnuoqTWQ==", "license": "BSD-3-Clause", "dependencies": { "commander": "^11.1.0", diff --git a/package.json b/package.json index 4902851..d865ff6 100644 --- a/package.json +++ b/package.json @@ -3,6 +3,6 @@ "tool:dns-records": "./script/dns-records" }, "dependencies": { - "@dotenvx/dotenvx": "^1.32.1" + "@dotenvx/dotenvx": "^1.34.0" } } diff --git a/script/dns-records b/script/dns-records index 3e8b484..29cab11 100755 --- a/script/dns-records +++ b/script/dns-records @@ -15,9 +15,9 @@ if [[ "$PWD" != "$GIT_ROOT" ]]; then fi if [ -z "${CI}" ]; then - dotenvx run -f .env.ci -- deno run -A "$GIT_ROOT/utils/dns-records.ts" "$@" + dotenvx run -f "$GIT_ROOT/.env.ci" -- deno run -A "$GIT_ROOT/utils/dns-records.ts" "$@" else - dotenvx run -f .env -- deno run -A "$GIT_ROOT/utils/dns-records.ts" "$@" + dotenvx run -f "$GIT_ROOT/.env" -- deno run -A "$GIT_ROOT/utils/dns-records.ts" "$@" fi exitcode=$? diff --git a/utils/dns-records.ts b/utils/dns-records.ts index 66f3ca7..3d67644 100755 --- a/utils/dns-records.ts +++ b/utils/dns-records.ts @@ -29,12 +29,7 @@ program.command("import") } const args = [ "run", - "--", - "octodns-dump", - "--config-file", - configFile, - "--output-dir", - dnsRecordsYamlDir + "dns-export" ] args.push(addTrailingDot(domain),`${provider || "cf"}`) console.log(`trying to exec ${whereCli} ${args.join(" ")}`) @@ -76,7 +71,7 @@ program.command("plan") if (Deno.env.get("CLOUDFLARE_TOKEN") == undefined) { throw new Error("Cloudflare API token missing, maybe forgot to set DOTENV_PRIVATE_KEY?") } - const args = ["run", "--", "octodns-sync", "--config-file", configFile] + const args = ["run", "dns-dryrun"] console.log(`trying to exec ${whereCli} ${args.join(" ")}`) const ops = new Deno.Command(whereCli, { args, @@ -118,7 +113,7 @@ program.command("apply") throw new Error("Cloudflare API token missing, maybe forgot to set DOTENV_PRIVATE_KEY?") } - const args = ["run", "--", "octodns-sync", "--config-file", configFile, "--doit"] + const args = ["run", "dns-apply"] if (opts.forceApply == true) { args.push("--force")