Warda-DNSDocs Warda: from ward — to protect, guardian
v0.7.5

Failover of the domains

Should the project lose control of Cloudflare (registrar of warda-dns.com and warda-dns.net, DNS of every zone, tunnel), the owner can, from OVH alone (registrar of warda-dns.fr and warda-dns.eu), move every box to warda-dns.fr for the online service and warda-dns.eu for the names of the boxes (internal/failover, internal/certs/previous.go, cmd/warda/failover.go).

  • The signed master record: a TXT record _warda-master.<domain> on warda-dns.com, .net, .fr and .eu, of one string (255 bytes at most): v=1;master=<com|net|fr|eu>;boxes=<com|net|fr|eu>;seq=<n>;sig=<sig>, fields in this exact order. master is the domain of the online service (cloud.<master domain>, customer area account.<master domain>), boxes the domain of the names of the boxes (<label>.warda-dns.<boxes>). seq: decimal, at least 1, no leading zero, 64 bits. sig: Ed25519 over the exact bytes before ;sig=, base64url without padding (86 characters, strict). Anything else is refused (quotes, an extra or missing field, upper case, padding, spaces, line breaks). A record that DNS split into several strings is joined back; the records that do not start with v=1; are skipped. The record is made by warda-cloud failover sign (see warda-cloud).
  • Trust: the public keys of the failover key are embedded in Warda (failover.Keys, several during a change of key); the key is different from every other key of the project. A record signed by another key, or not verifying, counts for nothing.
  • Reading: through the upstreams of the box (the way Warda resolves for itself, never a public resolver of its own), validated by Warda when it validates DNSSEC itself (a bogus answer is refused) — the signature is checked in every case. The valid record with the highest number over the four domains wins; the highest number ever accepted is kept (meta failover, with its record) and a lower one is never accepted again (rollback), even after a restart. No record anywhere: the record in force stays; never one accepted: the defaults.
  • Rhythm (task failover, Failover of the online service): 1 to 5 minutes after the start, every 6 hours give or take 30 minutes, and at once when 3 calls in a row to the online service fail (no answer, or an error 5xx of the service; a refusal 4xx is an answer) — at most once an hour for that.
  • What switches: every call to the online service (names and certificates, whoami, diagnostics, collective base, sites, plan and customer area, age of the domains, checks of the services, anonymous statistics) goes to https://cloud.<master domain>; the link of the customer area becomes https://account.<master domain>. An address given by the packaging or the administrator (-cloud-url / WARDA_CLOUD_URL) is kept whatever the record.
  • Names of the boxes (certificate given by Warda, mode warda): when boxes is not the domain of the name of the box, the box registers the same label under the new domain (POST /v1/boxes with domain), obtains its certificate (DNS-01 through the online service, PUT/DELETE /v1/boxes/acme with domain), and keeps serving the name of before until its certificate ends: DNS over TLS, HTTPS and QUIC choose the certificate by the name asked (SNI), and Warda answers both names with its own address. The name of before is never dropped while its certificate is valid (kept in tls/previous-<name>.pem, read again at each start, removed once ended). Network → DNS services then says: "This box is now named k3x9.warda-dns.eu. Devices set up with its former name k3x9.warda-dns.net (Android private DNS, profiles…) must be set up again with k3x9.warda-dns.eu: k3x9.warda-dns.net still works until <date>." Back to a domain of before, that name is the box again. Choosing another way for the certificate forgets the names of before.
  • System → Diagnostic shows "Online service: warda-dns.com (default)." or "Online service: warda-dns.fr (switched by record n° 2)."
  • API: GET /api/v1/failover (administrators, reading of the area system): active (a failover key is known), master, boxes, seq (the record in force; absent: none), accepted, checked, error (why the last check found nothing, or a record refused).
  • Off now: no failover key is in Warda yet (failover.Keys is empty): nothing is read, the task does not exist, and the box works exactly as before (warda-dns.com, names under warda-dns.net). A later version carries the public key made by the owner.