Mark Wooding [Mon, 8 Apr 2013 12:25:07 +0000 (13:25 +0100)]
hosts.lisp, distorted.lisp: Move anonymity services to jazz.
Mark Wooding [Sun, 7 Apr 2013 14:04:34 +0000 (15:04 +0100)]
binswood.lisp: Static allocation for Wifi client gadget.
Mark Wooding [Sun, 7 Apr 2013 14:01:26 +0000 (15:01 +0100)]
binswood.lisp, hosts.lisp: Move network definition to specific file.
Mark Wooding [Wed, 20 Mar 2013 22:51:16 +0000 (22:51 +0000)]
distorted.lisp, hosts.lisp: Evict records for mango.
Mark Wooding [Wed, 20 Mar 2013 22:50:37 +0000 (22:50 +0000)]
felixpearce.com: Move hosting to stratocaster.
Mark Wooding [Fri, 22 Feb 2013 09:54:47 +0000 (09:54 +0000)]
distorted.lisp: Host vox on jazz.
Mark Wooding [Sun, 10 Feb 2013 13:10:37 +0000 (13:10 +0000)]
binswood.lisp, hosts.lisp: Stable name and address for the printer.
Mark Wooding [Sun, 27 Jan 2013 20:52:44 +0000 (20:52 +0000)]
hosts.lisp, distorted.lisp: artist is on the untrusted network.
For some reason evo was still partially listed with that address.
Mark Wooding [Thu, 24 Jan 2013 21:07:09 +0000 (21:07 +0000)]
New domain `binswood.org.uk'.
Mark Wooding [Thu, 24 Jan 2013 21:05:59 +0000 (21:05 +0000)]
distorted.lisp: New zone for dynamic DNS service.
Mark Wooding [Thu, 24 Jan 2013 21:04:46 +0000 (21:04 +0000)]
Makefile: Prettify declaraions of other zones.
Mark Wooding [Fri, 18 Jan 2013 01:12:20 +0000 (01:12 +0000)]
distorted.lisp: Proxy pifi via artist for external users.
Mark Wooding [Thu, 17 Jan 2013 23:44:35 +0000 (23:44 +0000)]
distorted.lisp: Service name `pifi' for lounge jukebox
Mark Wooding [Thu, 17 Jan 2013 23:44:01 +0000 (23:44 +0000)]
distorted.lisp: Move main www service to stratocaster.
Mark Wooding [Thu, 17 Jan 2013 23:41:52 +0000 (23:41 +0000)]
Makefile: `vpn' is a preferred subnet for the inside view
Mark Wooding [Sun, 13 Jan 2013 22:11:03 +0000 (22:11 +0000)]
distorted.lisp: Give rawk a more sensible external address.
Mark Wooding [Sun, 13 Jan 2013 18:52:11 +0000 (18:52 +0000)]
hosts.lisp, distorted.lisp: Addresses for Raspberry Pi VPN devices.
Mark Wooding [Sun, 13 Jan 2013 18:51:54 +0000 (18:51 +0000)]
distorted.lisp: Move Git service to stratocaster.
Mark Wooding [Fri, 28 Dec 2012 22:49:47 +0000 (22:49 +0000)]
distorted.lisp, hosts.lisp: Move Kerberos, and use anycast.
Move the Kerberos master server to radius, and set up slave servers,
for performance and reliability, using anycast addresses.
Mark Wooding [Fri, 28 Dec 2012 17:56:46 +0000 (17:56 +0000)]
distorted.lisp: Move `rawk' server (back?) to artist.
Mark Wooding [Fri, 28 Dec 2012 17:55:32 +0000 (17:55 +0000)]
distorted.lisp: Announce `cabal' internal webserver.
Mark Wooding [Thu, 13 Dec 2012 17:48:38 +0000 (17:48 +0000)]
distorted.lisp: Move IRC server to jazz.
Mark Wooding [Sun, 9 Dec 2012 17:31:43 +0000 (17:31 +0000)]
distorted.lisp, hosts.lisp: Move iodine endpoint to jazz.
We no longer need the special address, because this is the only DNS
server jazz runs.
Mark Wooding [Sun, 9 Dec 2012 17:30:57 +0000 (17:30 +0000)]
distorted.lisp: Make roadstar the official house web proxy.
Mark Wooding [Sat, 8 Dec 2012 15:06:57 +0000 (15:06 +0000)]
Makefile, distorted.lisp: Deploy anycast services.
Mark Wooding [Sat, 25 Aug 2012 10:00:16 +0000 (03:00 -0700)]
hosts.lisp, distorted.lisp: Add Nicko's virtual server `richmond'.
Mark Wooding [Mon, 30 Jul 2012 00:31:08 +0000 (01:31 +0100)]
distorted.lisp: Announce an IRC server.
Mark Wooding [Thu, 26 Apr 2012 00:58:24 +0000 (01:58 +0100)]
Use precision as an official nameserver.
Withdraw vampire as an externally visible nameserver. It remains a
stealth secondary, and continues to serve internal views.
Mark Wooding [Wed, 25 Apr 2012 21:41:57 +0000 (22:41 +0100)]
distorted.lisp: Announce internal addresses for colocated servers.
Mark Wooding [Fri, 30 Mar 2012 22:51:00 +0000 (23:51 +0100)]
distorted.lisp: A new subzone `dnserr' full of wrong things.
Mark Wooding [Fri, 30 Mar 2012 22:50:00 +0000 (23:50 +0100)]
hosts.lisp, distorted.lisp: New `blackhole' address.
All IP packets to this address will be dropped silently. Useful for
strange testing.
Mark Wooding [Fri, 30 Mar 2012 22:48:02 +0000 (23:48 +0100)]
hosts.lisp, distorted.lisp: Allocate a separate address for iodine.
This is the only way of getting it to work, it seems. BIND9 can be
persuaded to serve using a nonstandard port, but it has no way to
forward to another server listening on such a port. This is obviously
crazy, but I'm still running a surplus of addresses.
Mark Wooding [Fri, 30 Mar 2012 22:44:39 +0000 (23:44 +0100)]
External zones don't need split-brain madness any more.
They used to require it when I didn't have a proper publicly routable
border network for the servers. So only generate `outside' views for
external zones. This also means I have to swap around the
`preferred-subnet-case' for choosing server addresses to favour
outside, but I think that's the right answer anyway.
Mark Wooding [Mon, 19 Mar 2012 14:01:51 +0000 (14:01 +0000)]
Makefile: Don't try to install io.
Mark Wooding [Mon, 19 Mar 2012 13:59:51 +0000 (13:59 +0000)]
distorted.lisp: Fix subnets for anycast service names.
Mark Wooding [Sat, 17 Mar 2012 15:17:50 +0000 (15:17 +0000)]
distorted.lisp, hosts.lisp: Publish addresses for anycast services.
Mark Wooding [Tue, 13 Mar 2012 17:15:04 +0000 (17:15 +0000)]
Makefile, distorted.lisp: Publish reverse zones.
Mark Wooding [Tue, 13 Mar 2012 15:04:36 +0000 (15:04 +0000)]
distorted.lisp: Remove obsidian from the list.
Its place was long gone anyway.
Mark Wooding [Mon, 12 Mar 2012 16:19:24 +0000 (16:19 +0000)]
distorted.lisp: New alias `git-master' for vampire.
Mark Wooding [Mon, 12 Mar 2012 16:18:17 +0000 (16:18 +0000)]
hosts.lisp: Carve out a chunk of address space for anycast.
Mark Wooding [Mon, 12 Mar 2012 14:41:20 +0000 (14:41 +0000)]
distorted.lisp: Add `evo' as an official alias for evolution.
Mark Wooding [Mon, 12 Mar 2012 14:38:20 +0000 (14:38 +0000)]
distorted.lisp: Add reverse records for trusted subnets individually.
Aand leave out the `safe' nertwork: otherwise, the PTR records overlap
with the CNAME records delegating DHCP-controlled addresses.
Mark Wooding [Mon, 12 Mar 2012 14:37:46 +0000 (14:37 +0000)]
hosts.lisp, distorted.lisp: Rename `virtual' network to `vpn'.
Mark Wooding [Mon, 12 Mar 2012 14:34:40 +0000 (14:34 +0000)]
hosts.lisp, distorted.lisp: Set up `safe' subnet.
Add interfaces on vampire and radius; move evolution to the new subnet.
Mark Wooding [Sun, 11 Mar 2012 04:58:39 +0000 (04:58 +0000)]
zone.lisp: The `colo' net doesn't really exist as such.
This is waiting on fender's guests and the VPN link being set up.
Mark Wooding [Sun, 11 Mar 2012 04:56:33 +0000 (04:56 +0000)]
distorted.lisp: Fix which network ranges are announced.
The `wired' net doesn't really exist as a coherent entity any more; and
the `unsafe', `untrusted' and `safe' networks are fairly well-defined,
really, so announce them properly.
Mark Wooding [Sun, 11 Mar 2012 04:55:28 +0000 (04:55 +0000)]
distorted.lisp: New role name `lpr'.
Mark Wooding [Sat, 3 Mar 2012 20:29:31 +0000 (20:29 +0000)]
hosts.lisp: Promote `safe' net.
The firewall configuration already assumed that I'd done this, but I
hadn't.
Mark Wooding [Mon, 27 Feb 2012 21:45:41 +0000 (21:45 +0000)]
hosts.lisp, distorted.lisp: Proper assignments for colocated servers.
Mark Wooding [Tue, 8 Nov 2011 17:37:24 +0000 (17:37 +0000)]
felixpearce.lisp: A records for web service.
Mark Wooding [Mon, 3 Oct 2011 19:01:59 +0000 (20:01 +0100)]
hosts.lisp, distorted.lisp: Separate address for anonymity services.
With a little luck, this will prevent most arsey Tor-blocking services
from rejecting innocent traffic.
Mark Wooding [Tue, 6 Sep 2011 14:35:34 +0000 (15:35 +0100)]
distorted.lisp: Publish information about the Kerberos setup.
Not that there is one yet.
Mark Wooding [Tue, 6 Sep 2011 10:00:41 +0000 (11:00 +0100)]
*.lisp: Change comment conventions slightly.
Remove the empty comments.
Mark Wooding [Sun, 4 Sep 2011 18:50:38 +0000 (19:50 +0100)]
distorted.lisp: Service name for rsync.
Mark Wooding [Sun, 4 Sep 2011 18:50:19 +0000 (19:50 +0100)]
New domain: felixpearce.com.
Mark Wooding [Tue, 19 Jul 2011 22:24:33 +0000 (23:24 +0100)]
distorted.lisp: Remove the dynamic zones.
I have to maintain them by hand anyway, so keeping them here is just
pointless.
Mark Wooding [Tue, 19 Jul 2011 20:45:39 +0000 (21:45 +0100)]
Makefile: Installation rules.
Primarily for zoneconf, though the hooks are pretty generic.
Mark Wooding [Tue, 19 Jul 2011 08:34:38 +0000 (09:34 +0100)]
distorted.lisp, harlequin.lisp, hosts.lisp: Reorgranization.
* Move the distorted host definitions into hosts.lisp, because harlequin
is still using raw hostnames which are being resolved.
* Qualify all of the basic host definitions.
* Move the name switch there too, and use unqualified hostnames to
indicate view-dependent mappings.
* Rename some of the networks, most obviously inet -> dmz.
Mark Wooding [Sat, 18 Jun 2011 19:49:05 +0000 (20:49 +0100)]
Makefile, distorted, harlequin: Rename `fretwank' to `internal'.
I think the time has come to take things a little more seriously.
Naah, not really. But I'll put on a good show.
Mark Wooding [Sun, 17 Jul 2011 18:17:02 +0000 (19:17 +0100)]
distorted.lisp: Remove pointless `@' in the top-level A record.
Mark Wooding [Sat, 18 Jun 2011 19:59:20 +0000 (20:59 +0100)]
Makefile: Replace the m4 crock with a proper GNU Make crock.
The m4 was an unmaintainable pile of horribleness. It needed
replacing. The only question is: have I replaced it with something
even worse?
An important new feature of the Makefile is that we can be interested in
different zones in each view. Previously, there was a list containing
the zones defined by the zoneset, and each view had to have the same
zones in it. There's now a list ZONESET_all_ZONES containing zones
common to all views in a zoneset, but there's also a variable
ZONESET_VIEW_ZONES for the zones which are specific to each view.
We've also made the separation between preferred subnets and views
clearer. Although we're still using the same names for both right now,
this will change soon. There's now a list of preferred subnets for each
view, and the feature keyword has changed to :VIEW/name.
This is important because the new publication machinery will object if
we try to feed it zones which it doesn't know about.
We also drop the various dynamic zones from publication, because they
always had to be maintained manually anyway.
Mark Wooding [Sun, 10 Jul 2011 21:16:57 +0000 (22:16 +0100)]
Major network reorganization.
There is now a new globally routable /28, used as a DMZ, and the
servers live on that as well as on the existing unsafe network (though
they've been renumbered). This also means that all of the old NAT
cruft must be swept away.
Life is hard, unfortunately: guvnor is too stupid to have the same
address on multiple network interfaces, so we must assign it two
addresses in the DMZ.
Mark Wooding [Sat, 18 Jun 2011 19:43:42 +0000 (20:43 +0100)]
hosts, distorted, harlequin: Drop boyle; adopt mythic-beasts.com.
I've lost the ability to administer boyle's nameserver, so I can't rely
on it continuing to be a secondary server for these zones. Remove it
from the list, and replace it with two of mythic-beasts.com's
nameservers since they generously provide secondary name service for
domains they register.
Mark Wooding [Sat, 11 Jun 2011 13:52:42 +0000 (14:52 +0100)]
distorted.lisp: New CNAME records for DHCP hosts.
Mark Wooding [Thu, 9 Jun 2011 10:27:04 +0000 (11:27 +0100)]
distorted.lisp: Reorganize services.
* Move metalzone's services to vampire's IP address. I know vampire
is still listening on metalzone's old address, but this seems more
honest. Some SSH clients might need tweaking as a result.
* Announce ibanez as the new NTP master. This is perhaps a little
premature, but I want its guests syncing from it (to minimize
network latency) and don't want to fiddle with the configuration
later.
Mark Wooding [Tue, 7 Jun 2011 12:28:57 +0000 (13:28 +0100)]
distorted.lisp: Move ibanez into the unsafe net.
Mark Wooding [Mon, 6 Jun 2011 10:21:07 +0000 (11:21 +0100)]
distorted.lisp: A name for radius on the untrusted network.
Mark Wooding [Mon, 6 Jun 2011 10:20:07 +0000 (11:20 +0100)]
distorted.lisp: Expose a name for vampire.
It's the same old NAT gateway, but what do you want?
Mark Wooding [Tue, 31 May 2011 12:29:29 +0000 (13:29 +0100)]
Merge branch 'master' of metalzone.distorted.org.uk:~mdw/public-git/zones
* 'master' of metalzone.distorted.org.uk:~mdw/public-git/zones:
Makefile.m4: Make the LaTeX documnt be optional.
harlequin.lisp: Use the statically defined address for `guvnor'.
distorted.lisp, harlequin.lisp: Use explicit filetype for `hosts.lisp'.
Mark Wooding [Tue, 31 May 2011 09:24:12 +0000 (10:24 +0100)]
distorted.lisp: Define addresses for all of the new machines.
New feature: we have CNAME records for some of our regular DHCP
clients.
Mark Wooding [Tue, 31 May 2011 09:22:29 +0000 (10:22 +0100)]
distorted.lisp: Merge together some of the role address definitions.
This way, it's slightly easier to see which servers are providing which
services, and moving roles between servers is a fairly simple kill-and-
yank operation.
Mark Wooding [Tue, 31 May 2011 09:20:01 +0000 (10:20 +0100)]
distorted.lisp: Full stops in section comments.
Mark Wooding [Sun, 22 May 2011 14:40:39 +0000 (15:40 +0100)]
Makefile.m4: Make the LaTeX documnt be optional.
Mark Wooding [Sun, 22 May 2011 14:39:19 +0000 (15:39 +0100)]
harlequin.lisp: Use the statically defined address for `guvnor'.
This avoids exercising the resolver for what's anyway a locally defined
name, and also avoids stressing the local search rules.
Mark Wooding [Sun, 22 May 2011 14:36:52 +0000 (15:36 +0100)]
distorted.lisp, harlequin.lisp: Use explicit filetype for `hosts.lisp'.
For some reason, CLisp didn't like it without.
Mark Wooding [Fri, 7 May 2010 08:35:48 +0000 (09:35 +0100)]
distorted.lisp: New VPN host `terror'.
Mark Wooding [Sat, 17 Apr 2010 18:27:51 +0000 (19:27 +0100)]
distorted.lisp: Service name for published `i2p' service.
Mark Wooding [Thu, 18 Feb 2010 09:35:50 +0000 (09:35 +0000)]
distorted.lisp: Carve an iodine subnet out of `untrusted'.
Mark Wooding [Sat, 25 Jul 2009 17:15:09 +0000 (18:15 +0100)]
distorted: Move news server to vampire.
Mark Wooding [Mon, 12 Jan 2009 21:45:08 +0000 (21:45 +0000)]
distorted: Add a service name for the Tor onion router.
Mark Wooding [Mon, 12 Jan 2009 21:44:23 +0000 (21:44 +0000)]
distorted: Switch around the ntp servers.
Now vampire is the primary. Currently both are getting time directly
from upstream.
Mark Wooding [Mon, 12 Jan 2009 21:43:40 +0000 (21:43 +0000)]
harlequin: Fix zone source address.
Mark Wooding [Wed, 10 Dec 2008 09:41:22 +0000 (09:41 +0000)]
distorted: Remove entry for evolution.fretwank.
evolution now only exists on the untrusted network.
Mark Wooding [Thu, 4 Dec 2008 14:19:25 +0000 (14:19 +0000)]
distorted: Renumbering evolution.
evolution is no longer the gateway to the untrusted net -- that's going
to be vampire now. Accordingly, give vampire.untrusted the .1 address.
Eventually, evolution simply won't need to exist on the trusted net, but
that's overly annoying right now. So its default name now corresponds
to its untrusted address, and the trusted .3 address will vanish later.
Mark Wooding [Wed, 26 Nov 2008 21:27:23 +0000 (21:27 +0000)]
distorted: Various changes.
* Merge the untrusted wired and wireless networks. There's no longer
any need for the wireless CIDR-delegation so delete it.
* Assign vampire an address in the untrusted network. This way it
can provide a VPN endpoint without messing up the routing completely.
* Assign crybaby a VPN address.
* Expunge tubescreamer and fuzzface.
Mark Wooding [Thu, 3 Apr 2008 19:16:14 +0000 (20:16 +0100)]
distorted: Provide ITS with its own little network.
ITS doesn't understand point-to-point links (bless), so humour it and
give it a little four-host network.
Also make the source file prettier.
Mark Wooding [Mon, 17 Mar 2008 09:33:17 +0000 (09:33 +0000)]
distorted: Add service vox.
Mark Wooding [Mon, 17 Mar 2008 09:32:59 +0000 (09:32 +0000)]
distorted: Remove duplicate PTR for evolution.wireless.
Mark Wooding [Sun, 16 Mar 2008 17:47:51 +0000 (17:47 +0000)]
harlequin: Rename blog site to `bindery'.
Mark Wooding [Sun, 16 Mar 2008 15:46:31 +0000 (15:46 +0000)]
harlequin: Add new service patchwork for blog.
Alas, this involves adding harlequin to the split-horizon-doom-thing.
Mark Wooding [Sun, 16 Mar 2008 15:06:33 +0000 (15:06 +0000)]
distorted: Provide SRV records for various obvious things.
Mark Wooding [Sun, 16 Mar 2008 15:04:44 +0000 (15:04 +0000)]
distorted, Makefile: Introduce the wireless reverse zone.
This is CIDR-delegated and set up for dynamic DNS population.
Mark Wooding [Sun, 16 Mar 2008 14:47:50 +0000 (14:47 +0000)]
distorted: Put NS glue in the reverse zones.
Rather than using the A records in the forward zones. It keeps the
zone definitions simpler for a start.
Mark Wooding [Wed, 15 Aug 2007 07:59:30 +0000 (08:59 +0100)]
Update for chiark moving to new IP address.
Mark Wooding [Wed, 15 Aug 2007 07:59:12 +0000 (08:59 +0100)]
Reformatting.
Mark Wooding [Wed, 15 Aug 2007 07:58:32 +0000 (08:58 +0100)]
New service names: wiki, db, ntp{,1}, and wpad.
Mark Wooding [Wed, 15 Aug 2007 07:57:11 +0000 (08:57 +0100)]
Add delegated reverse-zone for DHCP-allocated addresses.
Mark Wooding [Tue, 26 Jun 2007 15:35:55 +0000 (16:35 +0100)]
distorted: Move www-cache to vampire.
Mark Wooding [Mon, 25 Jun 2007 16:59:52 +0000 (17:59 +0100)]
Merge branch 'origin' -- abandoned work
* origin:
doc: Predump format for faster TeXing.
Mark Wooding [Mon, 25 Jun 2007 14:44:52 +0000 (15:44 +0100)]
distorted: Different nameservers inside and out; add vampire.
Also make the build system pass feature flags on so that we can build
the nameserver lists properly.