Files
automations/deployments/knot-dns/knot.conf
T
57_WolveandClaude Opus 5 54a5c0931a feat(knot-dns): authoritative Knot DNS node deployment
Native Alpine deployment for the anycast DNS estate -- no Docker, no Caddy,
alongside squid and openbao as an exception to the repo norm. Knot binds :53
directly, needs real client addresses for RRL and DNS cookies, and its DNSSEC
key store must live on the host filesystem.

Deploys a NODE. Zone data lives in the separate dns repo and arrives from its
pipeline. The split is /etc/knot/knot.conf: written here once as a skeleton of
include: lines covering only what belongs to a box (identity, NSID, storage
paths, listen, logging, control socket); everything that is DNS policy --
templates, dnssec policy, remotes/ACLs, modules, the domain inventory and the
zone files -- is delivered by the dns repo.

knsctl replaces adddns.pl and adddnssec.pl, fixing four defects:
- the duplicate check searched for the domain in BIND named.conf double-quote
  syntax (/"$domain"/) against unquoted YAML, so it could never match; only
  the -f zone-file test ever caught anything
- neither script consulted the other class's manifest, so a domain already in
  public.conf could be appended to dnssec.conf and fail the reload AFTER both
  files had been written
- nothing validated before reloading
- the reload was non-blocking, so a rejected config reported success

Its manifest matching is anchored on the YAML key and escapes the dot, so
barsrvno.de and srvnoXde no longer false-positive against srvno.de.

Aliases preserve the existing muscle memory with three corrections: -b on
every triggering knotc command (without it knotc returns OK when the command
was SENT, not when it succeeded); knzr (zone-reload) added alongside knrl
(reload), since reloading one zone's data is the right verb for a record
change and a full reload is only needed when a zone is added or removed; and
serial/NSID helpers that query unicast addresses, because asking the anycast
service address reaches whichever node is nearest and says nothing about
which node is stale.

Break-glass writes (add/remove/edit) warn and audit-log: they are overwritten
by the next pipeline deploy unless the change also lands in git. Removal
refuses to purge DNSSEC keys -- zone-purge +keys is irreversible on Knot
3.5.x, the key trash bin having arrived in 3.6.0 -- and prints the ordering
requirement, since removing a signed zone before the parent DS is withdrawn
is an outage for validating resolvers rather than a graceful shutdown.

deploy.sh, build.sh and cloud-init.yml are deliberately not included yet;
they are blocked on the Knot version decision, which sets the apk pin and
feature availability. See the Status section in the README.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-10 00:36:38 -05:00

52 lines
1.7 KiB
Plaintext

# knot.conf -- BOOTSTRAP SKELETON. Deployed once by deploy.sh; rarely changes.
#
# This file owns only what belongs to the BOX: identity, storage paths, listen
# addresses, logging, control socket. Everything that belongs to DNS POLICY --
# templates, dnssec policy, remotes/ACLs, modules, and the domain inventory --
# is delivered from the `dns` repo by its CD pipeline. Do not add zone: or
# template: sections here.
#
# Values in @UPPER@ are substituted by deploy.sh from .env.
#
# Reload: knotc -b conf-check && knotc -b reload
# The -b is not optional. Without it knotc returns OK when the command was
# *sent*, not when it succeeded -- a rejected zone file reports green.
server:
identity: "@NODE_ID@"
nsid: "@NODE_ID@"
rundir: "/run/knot"
user: knot:knot
automatic-acl: on
listen: [ @LISTEN@ ]
control:
listen: "/run/knot/knot.sock"
timeout: 0
log:
- target: syslog
server: warning
control: warning
zone: info # zone-load rejections and KSK-submission results log
# at info; at warning they are invisible
quic: warning
any: error
database:
storage: /var/lib/knot/database
journal-db: /var/lib/knot/journal
kasp-db: /var/lib/knot/keys
timer-db: /var/lib/knot/timer
catalog-db: /var/lib/knot/catalog
# --- delivered by the `dns` repo pipeline; see that repo's knot/ directory ---
include: /etc/knot/secrets.conf # rendered by deploy.sh, 0640 root:knot, NOT in git
include: /etc/knot/remotes.conf
include: /etc/knot/policy.conf
include: /etc/knot/modules.conf
include: /etc/knot/templates.conf
include: /etc/knot/arpa.conf
include: /etc/knot/dnssec.conf
include: /etc/knot/public.conf