Should the project lose control of Cloudflare (registrar of warda-dns.com
and warda-dns.net, DNS of every zone, tunnel), the owner can, from OVH
alone (registrar of warda-dns.fr and warda-dns.eu), move every box to
warda-dns.fr for the online service and warda-dns.eu for the names
of the boxes (internal/failover, internal/certs/previous.go,
cmd/warda/failover.go).
- The signed master record: a TXT record
_warda-master.<domain>on warda-dns.com, .net, .fr and .eu, of one string (255 bytes at most):v=1;master=<com|net|fr|eu>;boxes=<com|net|fr|eu>;seq=<n>;sig=<sig>, fields in this exact order.masteris the domain of the online service (cloud.<master domain>, customer areaaccount.<master domain>),boxesthe domain of the names of the boxes (<label>.warda-dns.<boxes>).seq: decimal, at least 1, no leading zero, 64 bits.sig: Ed25519 over the exact bytes before;sig=, base64url without padding (86 characters, strict). Anything else is refused (quotes, an extra or missing field, upper case, padding, spaces, line breaks). A record that DNS split into several strings is joined back; the records that do not start withv=1;are skipped. The record is made bywarda-cloud failover sign(see warda-cloud). - Trust: the public keys of the failover key are embedded in Warda
(
failover.Keys, several during a change of key); the key is different from every other key of the project. A record signed by another key, or not verifying, counts for nothing. - Reading: through the upstreams of the box (the way Warda resolves for
itself, never a public resolver of its own), validated by Warda when it
validates DNSSEC itself (a bogus answer is refused) — the signature is
checked in every case. The valid record with the highest number over the
four domains wins; the highest number ever accepted is kept (meta
failover, with its record) and a lower one is never accepted again (rollback), even after a restart. No record anywhere: the record in force stays; never one accepted: the defaults. - Rhythm (task
failover, Failover of the online service): 1 to 5 minutes after the start, every 6 hours give or take 30 minutes, and at once when 3 calls in a row to the online service fail (no answer, or an error 5xx of the service; a refusal 4xx is an answer) — at most once an hour for that. - What switches: every call to the online service (names and
certificates, whoami, diagnostics, collective base, sites, plan and
customer area, age of the domains, checks of the services, anonymous
statistics) goes to
https://cloud.<master domain>; the link of the customer area becomeshttps://account.<master domain>. An address given by the packaging or the administrator (-cloud-url/WARDA_CLOUD_URL) is kept whatever the record. - Names of the boxes (certificate given by Warda, mode
warda): whenboxesis not the domain of the name of the box, the box registers the same label under the new domain (POST /v1/boxeswithdomain), obtains its certificate (DNS-01 through the online service,PUT/DELETE /v1/boxes/acmewithdomain), and keeps serving the name of before until its certificate ends: DNS over TLS, HTTPS and QUIC choose the certificate by the name asked (SNI), and Warda answers both names with its own address. The name of before is never dropped while its certificate is valid (kept intls/previous-<name>.pem, read again at each start, removed once ended). Network → DNS services then says: "This box is now named k3x9.warda-dns.eu. Devices set up with its former name k3x9.warda-dns.net (Android private DNS, profiles…) must be set up again with k3x9.warda-dns.eu: k3x9.warda-dns.net still works until <date>." Back to a domain of before, that name is the box again. Choosing another way for the certificate forgets the names of before. - System → Diagnostic shows "Online service: warda-dns.com (default)." or "Online service: warda-dns.fr (switched by record n° 2)."
- API:
GET /api/v1/failover(administrators, reading of the areasystem):active(a failover key is known),master,boxes,seq(the record in force; absent: none),accepted,checked,error(why the last check found nothing, or a record refused). - Off now: no failover key is in Warda yet (
failover.Keysis empty): nothing is read, the task does not exist, and the box works exactly as before (warda-dns.com, names under warda-dns.net). A later version carries the public key made by the owner.