Skip to content

feat: check zone files for owners, ttl and cloudflare rules - #2

Open
jaspermayone wants to merge 2 commits into
mainfrom
feature-zone-checks
Open

jaspermayone wants to merge 2 commits into
mainfrom
feature-zone-checks

Conversation

@jaspermayone

Copy link
Copy Markdown
Member

What does this change?

This change adds tools/check_zones.py, which checks the repository rules that octoDNS does not check. ./bin/validate runs it, so the dns records check enforces it. It also brings the zone files in line with live Cloudflare, so they pass the new check.

New checks

The check fails when:

  • A record has no owner comment on the same line as its name. An email or a GitHub handle counts as an owner. TODO owner unknown does not.
  • A TTL is lower than 120 seconds, which is the Cloudflare minimum.
  • A zone file holds the apex NS records or the octodns-meta record.
  • A record that is not A, AAAA or CNAME is proxied.
  • A zone in config/config.yaml has no file, or a root YAML file is not a zone.
  • One name appears twice in one file.

This change adds 25 tests. One test confirms that a record from the nightly sync fails until someone gives it an owner.

Zone file changes

  • Every record now has the owner @patchworklabsorg/infra.
  • ttl: 1 becomes ttl: 120 on both zones. The ttl: 3600 on _gh-patchworklabsorg-o and google._domainkey on patchworklabs.org is removed, so they use the default of 600. All of these values match what Cloudflare serves now.
  • _dmarc on both zones matches the live value: np=reject is added, pct=100 is removed, and dmark_reports becomes dmarc_reports. Without this, the next deploy would undo the live DMARC change.

Deploy failures

  • Every deploy or Sync DNS run since 2025-11-05 has failed. The last run, on 2026-09-28, failed because CLOUDFLARE_TOKEN cannot see patchworklabs.org. octoDNS then tried to create the zone.
  • patchworklabs.org is in the "Patchwork Labs" Cloudflare account. hackathon.help is in the "Jasper Mayone" account. docs/runbook.md now describes how to make a user token that covers both zones.
  • idp, forms, admin.forms and www are in patchworklabs.org.yaml, but Cloudflare does not serve them. After the new token is in place, the first successful deploy will create them.

Checklist

  • ./bin/validate passes.
  • python -m unittest discover -s tools -p 'test_*.py' passes: 38 tests.
  • The octoDNS plan comment shows only the expected changes. This will not work until the token covers both zones.

@jaspermayone
jaspermayone requested review from a team as code owners September 28, 2026 20:48
@jaspermayone
jaspermayone requested review from youngchief-btw and removed request for a team September 28, 2026 20:48
@github-actions

Copy link
Copy Markdown

octoDNS plan

patchworklabs.org.

cloudflare

Operation Name Type TTL Value Source
Create Zone<patchworklabs.org.>
Create A 120 216.198.79.1 config
Create MX 120 '1 aspmx.l.google.com.'; '5 alt1.aspmx.l.google.com.'; '5 alt2.aspmx.l.google.com.'; '10 alt3.aspmx.l.google.com.'; '10 alt4.aspmx.l.google.com.' config
Create TXT 120 Owned by Patchwork Labs Inc (patchworklabs.org) a registered 501(c)(3) nonprofit organization.; google-site-verification=OjTBuEBXcUdIOVzjidh1sCMfvAYvabpQWnkGfFFQQA4; slack-domain-verification=ST5I2hJgX8CutN19stoedtub8ODxC2KwlHcbpKtb; stripe-verification=2EACE39B000887BB0491EB25506F91621A1E1097C9DE7C5C7C9E4E9F8701137E; v=spf1 include:_spf.google.com ~all config
Create _atproto TXT 120 did=did:plc:bpd7j2a34mmnyu7t64gzptg7 config
Create _dmarc TXT 120 v=DMARC1; p=quarantine; np=reject; rua=mailto:dmarc_reports@patchworklabs.org; ruf=mailto:dmarc_reports@patchworklabs.org; adkim=s; aspf=s config
Create _gh-patchworklabsorg-o TXT 600 cee2c56f89 config
Create admin.forms A 120 65.19.76.238 config
Create forms A 120 65.19.76.238 config
Create google._domainkey TXT 600 v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzEuGHXgOxIj0qk83hV4ajl/OIpXbhE/MTKhXU1VZDBISO/+yBCQsVyq1j4F13tWxUpYLlw78OJl+7TlAyZ4llYY5z2Oj+EiAIQZCRBLmKN7zDpnbwbiM4hfam5vnhCvFwdgg0aKUY221T/Pe5Mjz11e0VtyOJ3D3enPId010bi99p93Dimf+rFo9YFwps7U/V4O5rWaRyG9snFcl9tshvKTgQ6OoHEvLbvQIU1QTiXR6oHAI5KP/8BzA26djgIKqNuHaU9S70KSVUH/9CBSAjHP50j4i4rGGEr6PopNjxQxN5owwu2jUDEIOrv13RLpNPISu1NaPCgMnGVyfsQ77yQIDAQAB config
Create idp A 120 129.213.163.213 config
Create octodns-meta TXT 60 octodns-version=1.22.0; provider=cloudflare; time=2026-09-28T20:48:21.573486+00:00
Create openpgpkey CNAME 300 wkd.keys.openpgp.org. config
Create www CNAME 120 52fd2b2210caa11f.vercel-dns-017.com. config

Meta: {'cloudflare_plan': {'current': None, 'desired': 'free'}}

Summary: Creates=13, Updates=0, Deletes=0, Existing=0, Meta=True

hackathon.help.

cloudflare

Operation Name Type TTL Value Source
Create octodns-meta TXT 60 octodns-version=1.22.0; provider=cloudflare; time=2026-09-28T20:48:21.573486+00:00

Summary: Creates=1, Updates=0, Deletes=0, Existing=4, Meta=False


Planned against main with a read-only Cloudflare token. Only the zone files at the repository root are included. Changes to config/, bin/ or .github/ are not in this plan, so review those by hand.

@jaspermayone
jaspermayone added this pull request to stack #4 September 28, 2026 21:34

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant