feat: check zone files for owners, ttl and cloudflare rules - #2
Open
jaspermayone wants to merge 2 commits into
Open
jaspermayone wants to merge 2 commits into
jaspermayone wants to merge 2 commits into
Conversation
jaspermayone
requested review from
youngchief-btw
and removed request for
a team
September 28, 2026 20:48
octoDNS planpatchworklabs.org.cloudflare
Meta: {'cloudflare_plan': {'current': None, 'desired': 'free'}} Summary: Creates=13, Updates=0, Deletes=0, Existing=0, Meta=True hackathon.help.cloudflare
Summary: Creates=1, Updates=0, Deletes=0, Existing=4, Meta=False Planned against |
4 of 5 tasks
jaspermayone
added this pull request to stack #4
September 28, 2026 21:34
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this change?
This change adds
tools/check_zones.py, which checks the repository rules that octoDNS does not check../bin/validateruns it, so thedns recordscheck enforces it. It also brings the zone files in line with live Cloudflare, so they pass the new check.New checks
The check fails when:
TODO owner unknowndoes not.NSrecords or theoctodns-metarecord.A,AAAAorCNAMEis proxied.config/config.yamlhas no file, or a root YAML file is not a zone.This change adds 25 tests. One test confirms that a record from the nightly sync fails until someone gives it an owner.
Zone file changes
@patchworklabsorg/infra.ttl: 1becomesttl: 120on both zones. Thettl: 3600on_gh-patchworklabsorg-oandgoogle._domainkeyonpatchworklabs.orgis removed, so they use the default of 600. All of these values match what Cloudflare serves now._dmarcon both zones matches the live value:np=rejectis added,pct=100is removed, anddmark_reportsbecomesdmarc_reports. Without this, the next deploy would undo the live DMARC change.Deploy failures
deployorSync DNSrun since 2025-11-05 has failed. The last run, on 2026-09-28, failed becauseCLOUDFLARE_TOKENcannot seepatchworklabs.org. octoDNS then tried to create the zone.patchworklabs.orgis in the "Patchwork Labs" Cloudflare account.hackathon.helpis in the "Jasper Mayone" account.docs/runbook.mdnow describes how to make a user token that covers both zones.idp,forms,admin.formsandwwware inpatchworklabs.org.yaml, but Cloudflare does not serve them. After the new token is in place, the first successful deploy will create them.Checklist
./bin/validatepasses.python -m unittest discover -s tools -p 'test_*.py'passes: 38 tests.