Add LAN DNS profiles for separate primary and secondary hosts #4
No reviewers
Labels
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
kaiba/nixos-kaiba-network!4
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "codex/spiffe-lan-qualification"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Adds opt-in
lan-primaryandlan-secondaryNixOS modules for an Ace primary and a Mako secondary. The primary composes the existing SPIFFE updater/controller/publisher path and observes two physical DNS endpoints; the secondary runs a read-only Knot replica. The existing same-hostlan-qualificationprofile remains available as a separate software qualification fixture. Public-profile address and origin requirements remain unchanged.Both new profiles restrict TCP/UDP access to explicit LAN peers. Independent runtime TSIG keys separate loopback updates from host-scoped transfers and NOTIFY. Only the transfer secret is handed to the secondary through an operator-provisioned root-owned file; no secrets enter the Nix store. Persistent key/scope validation refuses missing, altered, linked, partial, or inconsistent material, including an absent credential tree alongside retained DNS journals.
Validation on 2026-09-29:
The new VM verifies real DNS transport between two VMs; it deliberately leaves the SPIFFE application services stopped. It does not establish the complete enrolled-device application path, native Ace/Mako operation, hardware or rollback qualification, public delegation, or public reachability. No live service, public record, delegation, or resolver was changed by this implementation. This draft stacks on
codex/spiffe-dns-integration.