diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..1230149 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,6 @@ +version: 2 +updates: + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "daily" diff --git a/.github/workflows/pr_preview.yml b/.github/workflows/pr_preview.yml index 23c0571..bd8e76f 100644 --- a/.github/workflows/pr_preview.yml +++ b/.github/workflows/pr_preview.yml @@ -20,10 +20,10 @@ permissions: # If you are using Method 3 (see below), this is where you will # set your env variables. -# env: -# MYCF_ACCOUNTID: "${{ secrets.MYCF_ACCOUNTID }}" -# MYCF_TOKEN: "${{ secrets.MYCF_TOKEN }}" -# +env: + GANDI_MAIN_SHARING_ID: "${{ secrets.GANDI_MAIN_SHARING_ID }}" + GANDI_MAIN_TOKEN: "${{ secrets.GANDI_MAIN_TOKEN }}" + jobs: preview: @@ -33,6 +33,8 @@ jobs: - name: Checkout repo uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0 + with: + persist-credentials: false # # Method 1: creds.json stored as a secret @@ -44,13 +46,12 @@ jobs: # Settings -> Secrets and variables -> Actions # i.e. https://github.com/YOUR_ORG/REPO_NAME/settings/secrets/actions # - - - - # Extract the secret and write it to the file. - name: Prepare creds_file - run: printf '%s' '${{secrets.CREDS_JSON}}' > creds.json - # +# - +# # Extract the secret and write it to the file. +# name: Prepare creds_file +# run: printf '%s' '${{secrets.CREDS_JSON}}' > creds.json + # Method 2: Dynamic creds.json file # # Store the individual credentials as github secrets, and dynamically generate diff --git a/.github/workflows/pr_push.yml b/.github/workflows/pr_push.yml index 328dab5..9baa01f 100644 --- a/.github/workflows/pr_push.yml +++ b/.github/workflows/pr_push.yml @@ -21,11 +21,11 @@ permissions: pull-requests: write # If you are using Method 3 (see below), this is where you will -# set your env variables. -# env: -# MYCF_ACCOUNTID: "${{ secrets.MYCF_ACCOUNTID }}" -# MYCF_TOKEN: "${{ secrets.MYCF_TOKEN }}" -# +# set your env variables. Add one line here for each env variable +# mentioned in creds.json. +env: + GANDI_MAIN_SHARING_ID: "${{ secrets.GANDI_MAIN_SHARING_ID }}" + GANDI_MAIN_TOKEN: "${{ secrets.GANDI_MAIN_TOKEN }}" jobs: push: diff --git a/README.md b/README.md index a9de0a1..4aaaf90 100644 --- a/README.md +++ b/README.md @@ -4,10 +4,19 @@ This repo stores our DNS Domains and records as "infrastructure as code" for our organization. The Github actions allow full "gitops" updates for our DNS infrastructure. All updates are done via PR. -## Steal this repo! + +## Clone this repo! Clone this repo as a starting point for your own organization's DNS-as-Code use. +1. Clone this repo. Give it a name appropriate for your organization (`dns-config` is suggested). +2. Update `.github/workflows/pr_preview.yml` and `.github/workflows/pr_push.yml` to use the credentials based on whether you use Method 1, 2 or 3 (see https://github.com/DNSControl/dnscontrol-action/blob/main/README.md) +3. Update `dnsconfig.js` to include example.com and one of your domains (start with a non-production domain). +4. Submit a PR, debug any auth issues. +5. Add other domains. See https://docs.dnscontrol.org/getting-started/getting-started for tips. +6. Update `README.md` to suit your organization. Delete this section. + + ## Updates To add/change/delete DNS records: @@ -43,3 +52,7 @@ Use your organization's approval process to review and approve the PR. **Step 5: Merge it!** On merger, a Github Action will run `dnscontrol push` to make the change. + +## How to get help + +FILL IN. diff --git a/creds.json b/creds.json new file mode 100644 index 0000000..fb941e4 --- /dev/null +++ b/creds.json @@ -0,0 +1,7 @@ +{ + "gandi_main": { + "TYPE": "GANDI_V5", + "sharing_id": "$GANDI_MAIN_SHARING_ID", + "token": "$GANDI_MAIN_TOKEN" + } +} diff --git a/dnsconfig.js b/dnsconfig.js index 107a770..bcb91b3 100644 --- a/dnsconfig.js +++ b/dnsconfig.js @@ -2,8 +2,8 @@ // To update types-dnscontrol.d.ts run: dnscontrol write-types -var REG_GANDI_TAL = NewRegistrar("gandi_v5_PLTS"); -var DNS_GANDI_TAL = NewDnsProvider("gandi_v5_PLTS"); +var REG_GANDI_TAL = NewRegistrar("gandi_main"); +var DNS_GANDI_TAL = NewDnsProvider("gandi_main"); var SPF_MXONLY = [TXT("@", "v=spf1 mx -all", TTL(3600))]; @@ -11,8 +11,8 @@ D("best-spaghetti-sauce-ever.com", REG_GANDI_TAL, DnsProvider(DNS_GANDI_TAL), SPF_MXONLY, - A("@", 142.93.29.52), - AAAA("@", 2604:a880:2:d1:0:1:2907:8001), + A("@", "142.93.29.52"), + AAAA("@", "2604:a880:2:d1:0:1:2907:8001"), MX("@", 1, "jj2.whatexit.org."), CNAME("www", "@"),