feat(web-arm): inbound IPv6 pilot — AAAA for web-arm.cloonar.com #82
Labels
No labels
bug
enhancement
in-progress
needs-info
needs-triage
p0
ready-for-agent
ready-for-human
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Cloonar/nixos#82
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What to build
Publish a single AAAA record
web-arm.cloonar.com -> 2a01:4f8:c012:43b::1(in the Hetzner-hostedcloonar.comzone), then confirm a real IPv6 client reaches web-arm end-to-end over v6 with a valid TLS cert. This proves the inbound path on a zero-user-impact name before any production site is dual-stacked.DNS for this fleet lives in the provider consoles (Hetzner DNS / Cloudflare), not in this repo (
updnsonly manages 2 dynamic names). So this is a manual DNS change plus live verification, not a code change.Acceptance criteria
web-arm.cloonar.com -> 2a01:4f8:c012:43b::1exists and resolvescurl -6 https://web-arm.cloonar.com) and gets the expected responseBlocked by
2a01:4f8:c012:43b::1reachable over v6 first