4 ms·
No DNS provider I've ever used has a way to store metadata alongside a DNS record (like an individual A record)
by ntoskrnl 4y ago
No DNS provider I've ever used has a way to store metadata alongside a DNS record (like an individual A record)
- paulgb 4y agoI was just about to give the same example. I’m more familiar with GCP’s DNS, but I don’t see a place for structured metadata in Route 53 either. https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-route53-recordset.html https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGui...
- georgyo 4y agoWhy do I need metadata along with my A record? It either exists or it doesn't. That is the state required for Terraform. The article explicitly mentions OctoDNS as a stateless configuration management system for DNS as a good solution.
- KyeRussell 4y agoTo know if it’s managed by TF or not, to know whether or not to delete it. Exactly what’s being described.
- NateEag 4y agoThat's what TXT records are for: https://en.m.wikipedia.org/wiki/TXT_record https://en.m.wikipedia.org/wiki/TXT_record
- gtirloni 4y agoExposed to the world?
- NateEag 4y agoI guess that's not ideal, though I'm not clear what attack surface area is increased by storing creation/ deletion metadata in public. I guess it lets an attacker know that you're using Terraform, which might help them target their attacks.
- ntoskrnl 4y agoTerraform can be used to manage TXT records too. Where does it store metadata for them? Or is it TXT all the way down?
- NateEag 4y agoYou can have multiple TXT records for a given domain name, so it would be possible to store an arbitrary amount of metadata for whatever systems you desire, and just loop through the TXT records to figure out which ones are for the current system's purpose.
- deleted 4y ago[deleted]
- rwmcfa1 4y agoIf you look through the octoDNS providers there's a number of cases where extra info is stored for "dynamic" records. The metadata is often things like the pool name or rule number. In other cases it's details about the health check config/version. The extra info is sometimes stored into a "notes" field, other times it's encoded into the ID or similar. It's true that nothing extra is needed for simple/standard records, but once you start doing GeoDNS, failover, health check, etc. it's required. In all cases thus far we've been able to find a way to store/indicate whatever we need. (maintainer of octoDNS)