Hacker News new | ask | show | jobs
by master_crab 18 days ago
Wait…what? You have a fully internal service and you dont have an internal DNS server? I guess those exist in theory, but not in practice. :)

If you have a heavy enough tech stack to run fully internal services, than you can also run an internal DNS service (even pihole is enough) and load internal only entries there.

Or add everything to your hosts file if you have a central config service.

1 comments

What, indeed. Yes, I have internal DNS servers. They are what handle the split horizons. How would one do split horizon without an internal DNS service?
You don’t. You avoid split horizon because of the silent (usually failure) mechanics it introduces.
I wasn't talking about your opinion of it, I was simply using a rhetorical question to point out the nonsensical premise of your response:

>Wait…what? You have a fully internal service and you dont have an internal DNS server?

You can't do split horizon without an internal DNS service. By definition it's a non-public service that gives separate results to public.

Because I was responding to this comment you had made:

So what's your solution when you have a wholly private service that will never have a public v4 address, nor a publicly routable v6? How do clients get the address for a nice domain name without the addresses in public DNS?

Which, if you claim you use private DNS, you know you can indeed solve by only having the private records sit on your private DNS service that can only be hit by clients on the internal network. Without the architectural bad practice of implementing split horizon.

Mate, what on Earth are you talking about? A private DNS server that can only be hit by clients on an internal network, which differs from public DNS, is split horizon.
Bless your sweet heart if you think private DNS servers are split horizon. :)