No description
  • Go 32.9%
  • Python 32.2%
  • Nix 26.9%
  • CSS 4.3%
  • HTML 3.1%
  • Other 0.6%
Find a file
Adam e1f18fbc35
Merge pull request #4 from pd-codex/codex/spiffe-lan-qualification
Add LAN DNS profiles for separate primary and secondary hosts
2026-10-01 00:16:36 -04:00
.github/workflows Add separate-host LAN DNS primary and secondary profiles 2026-09-29 10:54:53 -04:00
dns feat: authorize SPIFFE DNS workloads through fleet registry 2026-09-29 00:50:57 -04:00
docs Add separate-host LAN DNS primary and secondary profiles 2026-09-29 10:54:53 -04:00
nix/dns Add separate-host LAN DNS primary and secondary profiles 2026-09-29 10:54:53 -04:00
site refactor: make network repository DNS-only 2026-09-07 21:44:00 -04:00
tests Add separate-host LAN DNS primary and secondary profiles 2026-09-29 10:54:53 -04:00
.gitignore initial checkin 2026-08-09 21:23:58 -04:00
flake.lock refactor: make network repository DNS-only 2026-09-07 21:44:00 -04:00
flake.nix refactor: make network repository DNS-only 2026-09-07 21:44:00 -04:00
go.work feat: authorize SPIFFE DNS workloads through fleet registry 2026-09-29 00:50:57 -04:00
README.md Add separate-host LAN DNS primary and secondary profiles 2026-09-29 10:54:53 -04:00

Kaiba secure-device dynamic DNS

This repository contains the Kaiba dynamic DNS control-plane pilot. It gives devices stable DNS names without placing registrar credentials or hidden-origin topology on those devices.

Device software authenticates to the controller with mTLS and submits its complete public address set. The controller commits desired state to SQLite. A separate publisher projects that state to a writable hidden primary using RFC 2136 and TSIG, then verifies the result through redundant public authorities.

The opt-in two-host LAN profile places the writable primary on Ace and a read-only secondary on Mako, with a transfer-only runtime credential handoff. It retains the SPIFFE updater/controller authorization path and leaves public delegation and resolver settings unchanged. The earlier same-host qualification profile remains available for its isolated process-level tests.

Repository layout

  • dns/ contains the Go commands and private implementation packages.
  • nix/dns/ contains the standalone DNS flake and reusable NixOS modules.
  • tests/integration/ defines the seven-VM DNS topology.
  • tests/report/ renders and validates the deterministic evidence report.
  • site/ contains the static project site published with the latest report.
  • docs/ documents the DNS architecture and device-identity boundary.

Development

go test ./dns/...
nix --accept-flake-config fmt -- --ci
nix --accept-flake-config flake check --all-systems --no-build -L
nix flake check ./nix/dns --all-systems --no-build -L

Build the operator-facing DNS commands:

nix build .#kaiba-agent
nix build .#kaiba-controller
nix build .#kaiba-publisher

Run or build the integration topology:

nix run .#dns-test-driver
nix build .#dns-test-report -L
nix build .#dns-test-gate -L

Flake interface

The root flake is a convenience facade over nix/dns. Both expose:

  • packages: kaiba-agent, kaiba-controller, and kaiba-publisher;
  • NixOS modules for the device agent, update services, hidden primaries, hidden standbys, and public secondaries;
  • unit, module-evaluation, schema, security, topology, and report checks; and
  • the interactive dns-test-driver app on x86_64 Linux.

See the architecture for the control and data paths, and the device identity lifecycle for the platform-neutral credential contract.

Secure-device provisioning is maintained independently in PseudoDesign/kaiba-provisioning. This DNS repository does not import, re-export, build, test, or release its tools.