diff --git a/eight/per-domain/andref.yaml.nix b/eight/per-domain/andref.yaml.nix index 201d013..5ecef18 100644 --- a/eight/per-domain/andref.yaml.nix +++ b/eight/per-domain/andref.yaml.nix @@ -149,4 +149,24 @@ type = "A"; value = "100.110.15.98"; }; + + "public.testpage" = { + octodns.cloudflare = { + auto-ttl = true; + comment = "Test page hosted in milky-way, should be publicly accessible"; + }; + ttl = 60; + type = "A"; + value = generated.serverref.ipAddress; + }; + + "public-tailscale.testpage" = { + octodns.cloudflare = { + auto-ttl = true; + comment = "Test page hosted in milky-way, should not be accessible without Tailscale"; + }; + ttl = 60; + type = "A"; + value = generated.serverref.ipAddress; + }; } diff --git a/milky-way/environments/default/security.libsonnet b/milky-way/environments/default/security.libsonnet index d46e13f..e6d5210 100644 --- a/milky-way/environments/default/security.libsonnet +++ b/milky-way/environments/default/security.libsonnet @@ -107,9 +107,9 @@ local utils = import 'utils.libsonnet'; * In the future, this can be extended to deploy more test pages for other security scenarios. */ newTestPages( - publicDomain, // Domain for the public test page - publicDomainForTailscalePage, // Domain for the Tailscale-only test page (should be inaccessible but have a DNS record) - tailscaleDomain, // Domain for the Tailscale-only test page (should be accessible via Tailscale) + publicDomain, // Domain for the public test page. The DNS record should be public. + publicDomainForTailscalePage, // Domain for the Tailscale-only test page (should be inaccessible unless the device has Tailscale). The DNS record should be public. + tailscaleDomain, // Domain for the Tailscale-only test page (should be accessible via Tailscale). The DNS record should be private. name='security-testpages', ):: { local this = self,