Retire prepare-zones.sh pipeline; zones/ is now the served form

Big migration: the source/prepared split is gone. Each zones/*.zone is
now an RFC-compliant zone file that CoreDNS reads directly. Editing a
record is just edit + bump SOA + commit. CoreDNS auto-reloads within
30s; HE pulls on its own 300s SOA-refresh cycle.

Why: groundwork for the coredns-rfc2136 plugin to edit zones in place
without juggling a source/prepared transformation step. Also reduces
the mental model from "edit source, run prep, push" to just "edit".

Changes:
- zones/*.zone: 84 files migrated from Vultr-export form to RFC-compliant
  form (SOA injected, Vultr NS replaced with HE NS, CNAME/MX/NS rdata
  dot-terminated, apex lines get explicit @ prefix). Diff is mechanical
  and byte-count is unchanged (~340K) -- pure formatting promotion.
- docker-compose.yml: bind ./zones:/zones:ro (was ./zones-prepared)
- Makefile: dropped 'prep' target. 'reload' is now a no-op explainer.
  'tls-up' no longer depends on prep. 'clean' no longer wipes prepared.
- scripts/prepare-zones.sh moved to scripts/archive/ (kept for reference).
- .gitignore: updated comment for zones-prepared/ (now legacy).

NOT in this commit (follow-ups):
- CLAUDE.md updates documenting the new workflow.
- scripts/bump-serials.sh helper for manual-edit SOA bumping.
- coredns-rfc2136 plugin refactor (Phase 2b in the plan).
This commit is contained in:
Ryan Malloy 2026-05-21 11:14:42 -06:00
parent a9256f8ba4
commit 6d72d65642
88 changed files with 2125 additions and 795 deletions

View file

@ -1,19 +1,35 @@
; Zone file for acrazy.org
; Generated by mcp-vultr
; Auto-prepared by scripts/prepare-zones.sh on 2026-05-21T11:12:50-06:00
; Source: zones/acrazy.org.zone
$ORIGIN acrazy.org.
$TTL 3600
@ 3600 IN SOA ns1.he.net. admin.acrazy.org. (
2026052102 ; serial — bump per change (SERIAL=YYYYMMDDNN make prep)
300 ; refresh (5 min) — slaves poll us this often;
; tightened from 3600 to nudge HE's internal
; puller→anycast replication
120 ; retry (2 min) — kept < refresh per RFC 1912
604800 ; expire (1 week)
60 ; minimum (1 min) — negative-cache TTL on public
; resolvers; shrinks the window when an old
; NXDOMAIN keeps showing after we add a name
)
300 IN NS ns1.vultr.com
300 IN NS ns2.vultr.com
300 IN A 74.91.22.234
@ 3600 IN NS ns1.he.net.
@ 3600 IN NS ns2.he.net.
@ 3600 IN NS ns3.he.net.
@ 3600 IN NS ns4.he.net.
@ 3600 IN NS ns5.he.net.
@ 300 IN A 74.91.22.234
or 300 IN A 74.91.22.233
l 300 IN CNAME rpm-bullet.mer.idahomuellers.net
*.l 300 IN CNAME rpm-bullet.mer.idahomuellers.net
l 300 IN CNAME rpm-bullet.mer.idahomuellers.net.
*.l 300 IN CNAME rpm-bullet.mer.idahomuellers.net.
b 300 IN A 108.61.23.129
dootie 300 IN A 108.61.23.129
* 300 IN CNAME acrazy.org
*.dootie 300 IN CNAME dootie.acrazy.org
300 IN MX 10 acrazy.org
* 300 IN CNAME acrazy.org.
*.dootie 300 IN CNAME dootie.acrazy.org.
@ 300 IN MX 10 acrazy.org.
_acme-challenge 300 IN TXT "eIA2Ii4EA7cfmjVcTUvOrM5nc4nFRRYpjvxtpEYzPG4"
_acme-challenge 300 IN TXT "DQxkmE7D658WT3-MR5xa7x5NW85L0C8Xq80Iv9-ZF60"
_acme-challenge 300 IN TXT "uOz583TEOpuME0AiJgaZYusECS8VDCP55yBuGw9WL58"
@ -39,6 +55,4 @@ _acme-challenge.l 300 IN TXT "Ike1gqcB3VI7WwKoH3T8zqbpYSo2qRPrq0iqzB5wmFU"
_acme-challenge.langfuse.dootie 300 IN TXT "1WJ-mHJ2SQuuC5CgxbYY6euwiMZm1dVicfIkeluovTY"
_acme-challenge.dootie.l 300 IN TXT "uW30ozl6AKA_q9FWPlvaxuwbgBJ-TgTsXxA3JFtn0tg"
_acme-challenge.langfuse.dootie.l 300 IN TXT "P6tOVfwB8OBbI6AqnIuHXKQc05FjuABhGihUHwzpMOs"
; Explicit CNAMEs added to fix RFC 4592 empty-non-terminal cases
; (parent name has _acme-challenge children, so wildcard would skip it)
langfuse.dootie 300 IN CNAME acrazy.org
langfuse.dootie 300 IN CNAME acrazy.org.