Hacker News new | ask | show | jobs
by Walf 23 days ago
>Don't use split DNS

So what's your solution when you have a wholly private service that will never have a public v4 address, nor a publicly routable v6? How do clients get the address for a nice domain name without the addresses in public DNS?

I use acme.sh with DNS validation, and use common domains that have both public and private services on subdomains. I use split horizon so private.domain.example resolves only on LAN and VPN, and public.domain.example resolves everywhere, but the address changes depending on the network one is connected to.

2 comments

> How do clients get the address for a nice domain name without the addresses in public DNS?

They don’t. You put the addresses in public DNS.

Yeah, nah. Won't be doing that.
Why not? It's easy to set up and manage and it just points at an internal IP address
I consider that an unnecessary leak of private topology, it's not info that needs to be public. IPv6 addresses are not really ever internal, and an exploitable vulnerability in a firewall product leads to the possibility of a directly addressable target. Guessing a v6 address without a name pointing to it is impractical at best.
Wait…what? You have a fully internal service and you dont have an internal DNS server? I guess those exist in theory, but not in practice. :)

If you have a heavy enough tech stack to run fully internal services, than you can also run an internal DNS service (even pihole is enough) and load internal only entries there.

Or add everything to your hosts file if you have a central config service.

What, indeed. Yes, I have internal DNS servers. They are what handle the split horizons. How would one do split horizon without an internal DNS service?
You don’t. You avoid split horizon because of the silent (usually failure) mechanics it introduces.
I wasn't talking about your opinion of it, I was simply using a rhetorical question to point out the nonsensical premise of your response:

>Wait…what? You have a fully internal service and you dont have an internal DNS server?

You can't do split horizon without an internal DNS service. By definition it's a non-public service that gives separate results to public.

Because I was responding to this comment you had made:

So what's your solution when you have a wholly private service that will never have a public v4 address, nor a publicly routable v6? How do clients get the address for a nice domain name without the addresses in public DNS?

Which, if you claim you use private DNS, you know you can indeed solve by only having the private records sit on your private DNS service that can only be hit by clients on the internal network. Without the architectural bad practice of implementing split horizon.

Mate, what on Earth are you talking about? A private DNS server that can only be hit by clients on an internal network, which differs from public DNS, is split horizon.