From e4e0a432b99fc5baa7fe6ea03b2e06765298444e Mon Sep 17 00:00:00 2001 From: Tom Limoncelli Date: Mon, 17 Aug 2026 10:07:06 -0400 Subject: [PATCH 1/5] Fixing the config --- dnsconfig.js | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/dnsconfig.js b/dnsconfig.js index 107a770..bcb91b3 100644 --- a/dnsconfig.js +++ b/dnsconfig.js @@ -2,8 +2,8 @@ // To update types-dnscontrol.d.ts run: dnscontrol write-types -var REG_GANDI_TAL = NewRegistrar("gandi_v5_PLTS"); -var DNS_GANDI_TAL = NewDnsProvider("gandi_v5_PLTS"); +var REG_GANDI_TAL = NewRegistrar("gandi_main"); +var DNS_GANDI_TAL = NewDnsProvider("gandi_main"); var SPF_MXONLY = [TXT("@", "v=spf1 mx -all", TTL(3600))]; @@ -11,8 +11,8 @@ D("best-spaghetti-sauce-ever.com", REG_GANDI_TAL, DnsProvider(DNS_GANDI_TAL), SPF_MXONLY, - A("@", 142.93.29.52), - AAAA("@", 2604:a880:2:d1:0:1:2907:8001), + A("@", "142.93.29.52"), + AAAA("@", "2604:a880:2:d1:0:1:2907:8001"), MX("@", 1, "jj2.whatexit.org."), CNAME("www", "@"), From fac52b772c94a9ef6bf687fdadbaec56eec99b31 Mon Sep 17 00:00:00 2001 From: Tom Limoncelli Date: Mon, 17 Aug 2026 10:11:02 -0400 Subject: [PATCH 2/5] Fix creds --- .github/workflows/pr_preview.yml | 19 +++++++++---------- 1 file changed, 9 insertions(+), 10 deletions(-) diff --git a/.github/workflows/pr_preview.yml b/.github/workflows/pr_preview.yml index 23c0571..7737cc5 100644 --- a/.github/workflows/pr_preview.yml +++ b/.github/workflows/pr_preview.yml @@ -20,10 +20,10 @@ permissions: # If you are using Method 3 (see below), this is where you will # set your env variables. -# env: -# MYCF_ACCOUNTID: "${{ secrets.MYCF_ACCOUNTID }}" -# MYCF_TOKEN: "${{ secrets.MYCF_TOKEN }}" -# +env: + GANDI_MAIN_SHARING_ID: "${{ secrets.GANDI_MAIN_SHARING_ID }}" + GANDI_MAIN_TOKEN: "${{ secrets.GANDI_MAIN_TOKEN }}" + jobs: preview: @@ -44,13 +44,12 @@ jobs: # Settings -> Secrets and variables -> Actions # i.e. https://github.com/YOUR_ORG/REPO_NAME/settings/secrets/actions # - - - - # Extract the secret and write it to the file. - name: Prepare creds_file - run: printf '%s' '${{secrets.CREDS_JSON}}' > creds.json - # +# - +# # Extract the secret and write it to the file. +# name: Prepare creds_file +# run: printf '%s' '${{secrets.CREDS_JSON}}' > creds.json + # Method 2: Dynamic creds.json file # # Store the individual credentials as github secrets, and dynamically generate From 30f40bb40f5ed139ba3105ceb0106b967fd613a7 Mon Sep 17 00:00:00 2001 From: Tom Limoncelli Date: Mon, 17 Aug 2026 10:12:13 -0400 Subject: [PATCH 3/5] NEW FILE: creds.json --- creds.json | 7 +++++++ 1 file changed, 7 insertions(+) create mode 100644 creds.json diff --git a/creds.json b/creds.json new file mode 100644 index 0000000..fb941e4 --- /dev/null +++ b/creds.json @@ -0,0 +1,7 @@ +{ + "gandi_main": { + "TYPE": "GANDI_V5", + "sharing_id": "$GANDI_MAIN_SHARING_ID", + "token": "$GANDI_MAIN_TOKEN" + } +} From ea036d3bc4260aadc9386a4dc38834bcc1ed9111 Mon Sep 17 00:00:00 2001 From: Tom Limoncelli Date: Mon, 17 Aug 2026 10:22:51 -0400 Subject: [PATCH 4/5] Fix authentiation. Update docs. --- .github/workflows/pr_preview.yml | 2 ++ .github/workflows/pr_push.yml | 10 +++++----- README.md | 15 ++++++++++++++- 3 files changed, 21 insertions(+), 6 deletions(-) diff --git a/.github/workflows/pr_preview.yml b/.github/workflows/pr_preview.yml index 7737cc5..bd8e76f 100644 --- a/.github/workflows/pr_preview.yml +++ b/.github/workflows/pr_preview.yml @@ -33,6 +33,8 @@ jobs: - name: Checkout repo uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0 + with: + persist-credentials: false # # Method 1: creds.json stored as a secret diff --git a/.github/workflows/pr_push.yml b/.github/workflows/pr_push.yml index 328dab5..9baa01f 100644 --- a/.github/workflows/pr_push.yml +++ b/.github/workflows/pr_push.yml @@ -21,11 +21,11 @@ permissions: pull-requests: write # If you are using Method 3 (see below), this is where you will -# set your env variables. -# env: -# MYCF_ACCOUNTID: "${{ secrets.MYCF_ACCOUNTID }}" -# MYCF_TOKEN: "${{ secrets.MYCF_TOKEN }}" -# +# set your env variables. Add one line here for each env variable +# mentioned in creds.json. +env: + GANDI_MAIN_SHARING_ID: "${{ secrets.GANDI_MAIN_SHARING_ID }}" + GANDI_MAIN_TOKEN: "${{ secrets.GANDI_MAIN_TOKEN }}" jobs: push: diff --git a/README.md b/README.md index a9de0a1..4aaaf90 100644 --- a/README.md +++ b/README.md @@ -4,10 +4,19 @@ This repo stores our DNS Domains and records as "infrastructure as code" for our organization. The Github actions allow full "gitops" updates for our DNS infrastructure. All updates are done via PR. -## Steal this repo! + +## Clone this repo! Clone this repo as a starting point for your own organization's DNS-as-Code use. +1. Clone this repo. Give it a name appropriate for your organization (`dns-config` is suggested). +2. Update `.github/workflows/pr_preview.yml` and `.github/workflows/pr_push.yml` to use the credentials based on whether you use Method 1, 2 or 3 (see https://github.com/DNSControl/dnscontrol-action/blob/main/README.md) +3. Update `dnsconfig.js` to include example.com and one of your domains (start with a non-production domain). +4. Submit a PR, debug any auth issues. +5. Add other domains. See https://docs.dnscontrol.org/getting-started/getting-started for tips. +6. Update `README.md` to suit your organization. Delete this section. + + ## Updates To add/change/delete DNS records: @@ -43,3 +52,7 @@ Use your organization's approval process to review and approve the PR. **Step 5: Merge it!** On merger, a Github Action will run `dnscontrol push` to make the change. + +## How to get help + +FILL IN. From f24921aac6c4fe7582fa6354f699c39bf8d388d6 Mon Sep 17 00:00:00 2001 From: Tom Limoncelli Date: Mon, 17 Aug 2026 10:25:05 -0400 Subject: [PATCH 5/5] Add dependabot --- .github/dependabot.yml | 6 ++++++ 1 file changed, 6 insertions(+) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..1230149 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,6 @@ +version: 2 +updates: + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "daily"