3 ms·
I generally use hyphens instead of subdomains for SSL certificate purpose and go general-to-specific in the order: datacenter-application-environment-index.dom
by mediaserf 12y ago
I generally use hyphens instead of subdomains for SSL certificate purpose and go general-to-specific in the order:
datacenter-application-environment-index.domain.com
example:
ord-web-prod-01.domain.com
For clouds I use the cloud and zone/region:
rs-ord-web-prod-01.domain.com
aws-east1-app-stg-01.domain.com
- Alupis 12y agoI really dislike the suggestion of labeling devices by what they are. fwl, ups, pdu, rtr, swt, etc... all really give away too much info imho. Yes, someone may discover what the device is on their own via nmap -O or something, but telling someone up front this is a PDU and if you mess with it, it may crash an entire cabinet... is just... silly. I tend to follow the parent comment's suggestion more, labeling by location and environment (prod, dev, etc).
- DmitriRavinoff 12y agoAssuming you're doing split-horizon DNS, those records should be hidden from the outside. And the only way to detect the CNAMES other than brute force scanning of a DNS zone is to do a zone transfer. And you only have zone transfers allowed from other relevant DNS servers, right? And your monitoring software will catch a brute-force scan, right? Remember that the reverse dns always resolves to something like orange.example.com, which gives away no information at all.
- Alupis 12y agoNot if you don't control the DNS, and/or don't notice a crawl in the background network noise.
- tetha 12y agoOne thing to consider: .'s cooperate better with graphite, salt-stack and possibly ssh-configs, since in those tools, * matches everything but .; Thus, something like * .foo.* .* .domain.com.metric selects the metric for all datacenters & environments for the application foo. Using hypens, this doesn't work. (Why can't I escape * 's? ....)