Add LAN DNS profiles for separate primary and secondary hosts #4

Merged
ams-tech merged 2 commits from codex/spiffe-lan-qualification into main 2026-10-01 00:16:36 -04:00
ams-tech commented 2026-09-29 03:29:23 -04:00 (Migrated from github.com)

Adds opt-in lan-primary and lan-secondary NixOS modules for an Ace primary and a Mako secondary. The primary composes the existing SPIFFE updater/controller/publisher path and observes two physical DNS endpoints; the secondary runs a read-only Knot replica. The existing same-host lan-qualification profile remains available as a separate software qualification fixture. Public-profile address and origin requirements remain unchanged.

Both new profiles restrict TCP/UDP access to explicit LAN peers. Independent runtime TSIG keys separate loopback updates from host-scoped transfers and NOTIFY. Only the transfer secret is handed to the secondary through an operator-provisioned root-owned file; no secrets enter the Nix store. Persistent key/scope validation refuses missing, altered, linked, partial, or inconsistent material, including an absent credential tree alongside retained DNS journals.

Validation on 2026-09-29:

  • New two-host QEMU TCG VM passed eight groups in 127 seconds: cross-host initial AXFR; NOTIFY propagation; update/transfer permission separation and read-only secondary; early TCP/UDP source firewall; host/user credential separation; independent primary outage with secondary journal recovery and catch-up; persistent key reuse with missing/changed-import refusal; and lost credential-tree refusal with retained journal state.
  • The earlier same-host qualification profile has its separate 15-check VM covering a primary and two replica processes. That result does not establish independent-host redundancy.
  • New and existing module evaluation checks, CI workflow syntax, Nix formatting, and all-system flake evaluation passed. CI runs both focused profiles and retains their distinct result artifacts.

The new VM verifies real DNS transport between two VMs; it deliberately leaves the SPIFFE application services stopped. It does not establish the complete enrolled-device application path, native Ace/Mako operation, hardware or rollback qualification, public delegation, or public reachability. No live service, public record, delegation, or resolver was changed by this implementation. This draft stacks on codex/spiffe-dns-integration.

Adds opt-in `lan-primary` and `lan-secondary` NixOS modules for an Ace primary and a Mako secondary. The primary composes the existing SPIFFE updater/controller/publisher path and observes two physical DNS endpoints; the secondary runs a read-only Knot replica. The existing same-host `lan-qualification` profile remains available as a separate software qualification fixture. Public-profile address and origin requirements remain unchanged. Both new profiles restrict TCP/UDP access to explicit LAN peers. Independent runtime TSIG keys separate loopback updates from host-scoped transfers and NOTIFY. Only the transfer secret is handed to the secondary through an operator-provisioned root-owned file; no secrets enter the Nix store. Persistent key/scope validation refuses missing, altered, linked, partial, or inconsistent material, including an absent credential tree alongside retained DNS journals. Validation on 2026-09-29: - New two-host QEMU TCG VM passed eight groups in 127 seconds: cross-host initial AXFR; NOTIFY propagation; update/transfer permission separation and read-only secondary; early TCP/UDP source firewall; host/user credential separation; independent primary outage with secondary journal recovery and catch-up; persistent key reuse with missing/changed-import refusal; and lost credential-tree refusal with retained journal state. - The earlier same-host qualification profile has its separate 15-check VM covering a primary and two replica processes. That result does not establish independent-host redundancy. - New and existing module evaluation checks, CI workflow syntax, Nix formatting, and all-system flake evaluation passed. CI runs both focused profiles and retains their distinct result artifacts. The new VM verifies real DNS transport between two VMs; it deliberately leaves the SPIFFE application services stopped. It does not establish the complete enrolled-device application path, native Ace/Mako operation, hardware or rollback qualification, public delegation, or public reachability. No live service, public record, delegation, or resolver was changed by this implementation. This draft stacks on `codex/spiffe-dns-integration`.
Sign in to join this conversation.
No description provided.