
We have three groups adns : the hidden primary bind server ns : the secondary public authoratitive servers dns : both of the above Only the primary server needs to clone the bind config repos and notify the secondary servers on updates. So the dns_repos and dns_notify arguments can go into adns.yaml so they're only available to the primary server. Only the secondary servers need to know the ip address of the master/primary server so it can allow itself to be notified by that IP, and do transfer requests. So dns_master_ipv<4|6> can live in ns.yaml This leaves in dns.yaml the one thing both have to agree on, which is the zones to transfer betwen each other. Change-Id: Ibd8063e92ad7ff9ee683dcc7dfcc115a0b19dcaa
8 lines
169 B
YAML
8 lines
169 B
YAML
dns_master_ipv4: 104.239.146.24
|
|
dns_master_ipv6: 2001:4800:7819:104:be76:4eff:fe04:43d0
|
|
|
|
iptables_extra_public_tcp_ports:
|
|
- 53
|
|
iptables_extra_public_udp_ports:
|
|
- 53
|