Restructure around a single entry point (automations.sh) with a Gum wizard and a self-extracting bundle for repo-less installs. Add scripts/oslib.sh so the provisioning scripts (setup-host, harden-ssh, harden-jumphost, sshuser) run on Alpine/Debian/Alma; seed root keys from globals/. - ntfy SSH-login alerts (user, source IP, key, region, jump target) via pam_exec - daily auto-updates with AUTO_REBOOT=idle (reboots only when no SSH active) and opt-in Alpine stable-branch upgrades - generic + per-deployment cloud-init; Gitea release workflow on tag - README/LICENSE/.gitignore/.gitattributes (force LF); repo URLs -> Gitea
2.8 KiB
1. General Information
1.01 This section contains regulations for identification of network systems, devices, and applications or services.
1.02 Whenever this section is reissued, the reason(s) for reissue will be listed in this paragraph.
2. Identification & Configuration
2.01 Provides a common method and standard for universal identification of systems, devices, and software or services with a Domain Name for DNS.
3. Network Domain Name Schema
3.01 Table of acronymized abbreviations for use in DNS.
Names for Applications & Services:
- app – Application Server (non-web)
- dbs – Database Server
- ftp – SFTP server
- mta – Mail Server / Mail Transfer Agent
- dns – Name Server
- rsv - DNS Rsolver
- cfg – Configuration Management (puppet/ansible/etc.)
- mon – Monitoring Server (nagios, sensu, etc.)
- zbx - Zabbix Proxy / Server
- ssh – SSH Jump/Bastion Host
- sto – Storage Server / File Share (iSCSI/NFS/SMB/Ceph/GlusterFS)
- git – Version Control Software Server (Git/SVN/CVS/etc.)
- vmm – Virtual Machine Manager
- web – Web Server k8s - Kubernetes Controller/Worker Node
- dsv - Directory Domain Services (LDAP / AD DS)
- rds - Remote Desktop Services - (RemoteApp/Sessions)
- vpn – VPN Gateway
- wgd – WireGuard
- prx – Proxy/Load Balancer (software)
- zta - Zero Trust Access
- dot - Traffic Shaper
Names for Systems and Devices:
- con – Console/Terminal Server
- fwl – Firewall
- lbl – Load Balancer (physical)
- gtr - L3 Global Transit Router
- ctr - L3 Core Router
- rtr – L3 Router
- swt – L2 Switch
- dcr – Data Center Router
- dcs – Data Center Switch
- pdu – Power Distribution Unit
- ups – Uninterruptible Power Supply
3.02 Geospatial positioning in domain names for regional datacenter services and systems is to follow UN/LOCODE naming conventions as follows:
Example: us-evi-1.example.net indicates the names
left most of ‘us-evi-1' are in Elk Grove Village Illinois within the United States of America. The trailing number “1” indicates the specific facility located in this municipality for cases where multiple are within the same regional area.
Application of this USP can be demonstrated as followed:
Example: dns-1.us-evi-1.datacenter.gg
3.03 Anycast services do not follow 3.02, instead indicate region using anycast in placement of 3.02 region code. Section 3.02 may still be used for secondary IPs that are bound to the location, even to the same service.
Example: dns-1.anycast.datacenter.gg
4. UN/LOCODE Code List by Country and Territory
4.01 Data Located in Online Resource
URL: https://unece.org/trade/cefact/unlocode-code-list-country-and-territory