cloudflare-dns: a public-dns provider (ADR 0049)

The first registrar behind the neutral public-dns interface. Provider shape
like minio: provides public-dns, a provisioner that registers a consumer's
public name at Cloudflare pointing it at the mesh's ingress, and removes it on
withdrawal. The name is derived from the consumer identity under the mesh's
domain (so stateless teardown recomputes it); the returned {fqdn,target,ttl}
is public, the Cloudflare token the only secret and it never leaves. Emits
record.created/.removed (best-effort). A cloudflare_dns_records diagnostic tool.
Config (zone, domain, ingress) is left to settings, so it fails closed until a
mesh provides them. Typechecks; manifest parses.
This commit is contained in:
2026-09-04 20:55:36 +02:00
parent 0e102dd350
commit d2d20a76b6
6 changed files with 262 additions and 0 deletions
@@ -0,0 +1,43 @@
// cloudflare-dns's provisioner — the adapter making it a provider of the mesh `public-dns` interface
// (novox/hq ADR 0049). The reconcile loop, sealing and grant-file handling are the sdk harness's;
// this writes only the per-registrar half: register a consumer's public name at Cloudflare, pointing
// it at the mesh's ingress, and remove it when the grant is withdrawn.
//
// The `public-dns` interface hands a consumer { fqdn, target, ttl } — a name that resolves publicly
// and what it resolves to. It is not a secret (a DNS record is public), so nothing is sealed beyond
// what the harness seals; the only secret is this module's own Cloudflare token, which never leaves.
import { runProvisioner, type Grant, type Credential } from "@novox/mesh-sdk/provisioner";
import { emit } from "@novox/mesh-sdk/events";
import { CloudflareClient } from "../client.js";
const cloudflare = CloudflareClient.fromEnv();
runProvisioner("public-dns", {
async create(grant: Grant): Promise<Credential> {
const fqdn = cloudflare.nameFor(grant.consumer);
await cloudflare.upsert(fqdn);
await announce("module.cloudflare-dns.record.created", {
name: fqdn,
target: cloudflare.ingress,
consumer: grant.consumer,
node: grant.node,
});
return { fields: { fqdn, target: cloudflare.ingress, ttl: "300" } };
},
async remove(grant: Grant): Promise<void> {
const fqdn = cloudflare.nameFor(grant.consumer);
await cloudflare.remove(fqdn);
await announce("module.cloudflare-dns.record.removed", { name: fqdn, consumer: grant.consumer, node: grant.node });
},
});
/** Emit best-effort: a broker hiccup must never fail or reverse a DNS change that already happened. */
async function announce(type: string, body: unknown): Promise<void> {
try {
await emit(type, body);
} catch (err) {
console.error(`[cloudflare-dns] could not emit ${type}: ${err}`);
}
}