Files
homelab-infra/infrastructure/dns/records.yml
T
panxiao81andClaude Opus 5.5 45437f27d0
ansible / collection-test (pull_request) Successful in 2m12s
yaml / yaml (pull_request) Successful in 2m27s
ansible / lint (pull_request) Successful in 2m48s
补回旧工作区中仅存于本地的 Backstage OIDC、DNS 与 agent 说明
清理 chore/recover-old-workspace 时发现以下内容已在线上使用,却只存在于未提交的工作区:

- Authelia `backstage` OIDC client(与 helm 现网 values 逐键比对一致;仅含 pbkdf2 哈希,
  与既有 client 写法相同)。
- `backstage.ad.ddupan.top` A 记录(现网已解析到 192.168.10.127)。
- CLAUDE.md:VyOS `cli-shell-api showConfig` 尾随节点名不会过滤、会输出含密钥的完整配置。
- .agents/skills/homelab-knowledge:让 agent 查询与维护 homelab-wiki 的技能说明。

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-10-01 17:30:07 +00:00

83 lines
3.9 KiB
YAML
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
# Homelab DNS desired state. This file is the canonical inventory; individual
# backends consume only the views they own.
homelab_dns:
samba:
# Samba remains authoritative for the AD zone. Only these explicitly listed
# RRsets are reconciled; Samba-generated AD/Kerberos records are untouched.
records:
- { zone: ad.ddupan.top, name: bao, type: A, values: [192.168.10.8] }
- { zone: ad.ddupan.top, name: pve1, type: A, values: [192.168.10.4] }
- { zone: ad.ddupan.top, name: pve2, type: A, values: [192.168.10.7] }
- { zone: ad.ddupan.top, name: pve3, type: A, values: [192.168.10.9] }
- { zone: ad.ddupan.top, name: sandbox1, type: A, values: [10.60.0.11] }
- { zone: ad.ddupan.top, name: sandbox2, type: A, values: [10.60.0.12] }
- { zone: ad.ddupan.top, name: sandbox-k8s, type: A, values: [10.60.0.13] }
- { zone: ad.ddupan.top, name: retrolab, type: A, values: [10.60.0.10] }
- { zone: ad.ddupan.top, name: grafana, type: A, values: [192.168.10.127] }
- { zone: ad.ddupan.top, name: metrics-write, type: A, values: [192.168.10.127] }
- { zone: ad.ddupan.top, name: netbox, type: A, values: [192.168.10.127] }
- { zone: ad.ddupan.top, name: nats, type: A, values: [192.168.10.127] }
- { zone: ad.ddupan.top, name: nexus, type: A, values: [192.168.10.127] }
- { zone: ad.ddupan.top, name: s3, type: A, values: [192.168.10.127] }
- { zone: ad.ddupan.top, name: hydra, type: A, values: [192.168.10.127] }
- { zone: ad.ddupan.top, name: hydra-login, type: A, values: [192.168.10.127] }
- { zone: ad.ddupan.top, name: spire-oidc, type: A, values: [192.168.10.127] }
- { zone: ad.ddupan.top, name: spire-server, type: A, values: [192.168.10.127] }
- { zone: ad.ddupan.top, name: zot, type: A, values: [192.168.10.127] }
- { zone: ad.ddupan.top, name: zot-push, type: A, values: [192.168.10.127] }
- { zone: ad.ddupan.top, name: backstage, type: A, values: [192.168.10.127] }
- { zone: ad.ddupan.top, name: pg-prod, type: A, values: [192.168.10.2] }
- { zone: ad.ddupan.top, name: pg-dev, type: A, values: [192.168.10.127] }
split_horizon:
# backends records the current adoption boundary. obj is deliberately not
# emitted to CoreDNS yet, preserving the current pod resolver behaviour.
records:
- { name: git.ddupan.top, type: A, values: [192.168.10.127], backends: [blocky, coredns] }
- { name: auth.ddupan.top, type: A, values: [192.168.10.127], backends: [blocky, coredns] }
- { name: obj.ddupan.top, type: A, values: [192.168.10.127], backends: [blocky] }
public:
# Names expected at Cloudflare. Terraform adoption is a separate change;
# complete RRsets here make the current ownership gap explicit.
records:
- name: auth.ddupan.top
type: CNAME
values: [ff392451-b0b1-45bb-964e-6d9372c3a9e3.cfargotunnel.com]
proxied: true
terraform:
managed: true
resource_name: auth
- name: git.ddupan.top
type: CNAME
values: [ff392451-b0b1-45bb-964e-6d9372c3a9e3.cfargotunnel.com]
proxied: true
terraform: { managed: false }
- name: obj.ddupan.top
type: CNAME
values: [ff392451-b0b1-45bb-964e-6d9372c3a9e3.cfargotunnel.com]
proxied: true
terraform: { managed: false }
- name: e5renew.ddupan.top
type: CNAME
values: [ff392451-b0b1-45bb-964e-6d9372c3a9e3.cfargotunnel.com]
proxied: true
terraform: { managed: false }
# OCI 主机直接解析公网 IP,SSH 不经过 Cloudflare 代理。
- name: oci-arm.ddupan.top
type: A
values:
- 129.225.138.179
proxied: false
ttl: 300
terraform: { managed: false }
- name: oci-amd.ddupan.top
type: A
values:
- 129.225.176.134
proxied: false
ttl: 300
terraform: { managed: false }