YC K8s KMS NLB ALB Lockbox DNS CL CR
December 22, 2022

Cloud DNS нюансы

Здесь описаны нюансы работы DNS и Cloud DNS.

DNS

  1. Если в поддомене с wildcard есть TXT запись, то такой домен не считается пустым и не подпадает под wildcard.

Пример:

Есть запись _acme-challenge.payments-api-public.dev.my-health.tech. TXT
При наличии такой записи поддомен payments-api-public.dev.my-health.tech.считается непустым и не попадает под wildcard.

dig payments-api-public.dev.my-health.tech +noall +answer
нет ответа

Cloud DNS

  1. Не поддерживается DNSSEC.

Утилиты для работы с DNS

dig cameda1.ml +noall +answer
dig NS cameda1.ml +noall +answer
dig SOA cameda1.ml +noall +answer
dig MX cameda1.ml +noall +answer
dig SRV cameda1.ml +noall +answer
dig TXT cameda1.ml +noall +answer
dig CNAME cameda1.ml +noall +answer
dig cameda1.ml +short
158.160.45.149
dig cameda1.ml +trace

; <<>> DiG 9.10.6 <<>> cameda1.ml +trace
;; global options: +cmd
.			478149	IN	NS	f.root-servers.net.
.			478149	IN	NS	g.root-servers.net.
.			478149	IN	NS	h.root-servers.net.
.			478149	IN	NS	i.root-servers.net.
.			478149	IN	NS	j.root-servers.net.
.			478149	IN	NS	k.root-servers.net.
.			478149	IN	NS	l.root-servers.net.
.			478149	IN	NS	m.root-servers.net.
.			478149	IN	NS	a.root-servers.net.
.			478149	IN	NS	b.root-servers.net.
.			478149	IN	NS	c.root-servers.net.
.			478149	IN	NS	d.root-servers.net.
.			478149	IN	NS	e.root-servers.net.
.			478149	IN	RRSIG	NS 8 0 518400 20230103150000 20221221140000 18733 . bu3NTh6jn031a7htOxjGqfu/GOSw+afaYH394m1Jh41/yknldkT0hWPs JoRiwSQndeI7nuOtgpfVlo/GDtAoKHLx/36kiOOVw2b9wYN5uOvHwYic rXoCwsM4Uu9qT99vpqKCJ6q5ZgDYkzJ8nmtrGhdOCsnWD2ZIqKwRIPh1 d3+vvwNam1GwNsC0zYVWqU9ZPqvTIRFZInCOGCmJ/CGFGCahmBSwDdNL IUVS9IROHgVTgDIOwkM7WwK594KjfEBVZFGlXEHxb91BfqwE5rqkh11d kUI9iZvBu1v+j5dr03soLKJCNHXFwhf73btHCN+ZP8XGtDcD1qAW2Oam oKU23Q==
;; Received 1097 bytes from 2a02:6b8:0:419::1#53(2a02:6b8:0:419::1) in 9 ms

ml.			172800	IN	NS	a.ns.ml.
ml.			172800	IN	NS	b.ns.ml.
ml.			172800	IN	NS	c.ns.ml.
ml.			172800	IN	NS	d.ns.ml.
ml.			86400	IN	NSEC	mlb. NS RRSIG NSEC
ml.			86400	IN	RRSIG	NSEC 8 1 86400 20230104050000 20221222040000 18733 . gVZh+r5AJdXJIkw66McBo+hZbwULXT6NcBsPiRfijrslZP6iWAsYKTc9 537fb3KkoOixpzSaR5vVxbTuFEKHcGdbc+TMIt4V4h8cVzvPW7a1oOnF b4Hh8JmiTrd4/RPyhrskLomku3QzCUHq0rFUsMfcF3Nt6wrqyF3rWoAC 0Zh6zkp4phai4EiWkBbCP6y9LT9WeKW8eGrau31afmSfVg7tX9VvmTAJ PiLqYlucAPdSeUge+w169sVV8C6CWM+zwyXcnMCBkbNG11fEYBMEx3/3 uBdPVMTnSYRslx9QvcQe80I2e4w9DsLvh/Ok+SV2uW86KaTik/1Dovvc Z9XQcw==
;; Received 594 bytes from 193.0.14.129#53(k.root-servers.net) in 15 ms

cameda1.ml.		300	IN	NS	ns2.yandexcloud.net.
cameda1.ml.		300	IN	NS	ns1.yandexcloud.net.
;; Received 90 bytes from 185.21.169.1#53(b.ns.ml) in 261 ms

cameda1.ml.		600	IN	A	158.160.45.149
;; Received 65 bytes from 84.201.189.229#53(ns2.yandexcloud.net) in 10 ms
dig debug cameda1.ml