# Multi-Tenant DNS Server Setup ## ๐ŸŽฏ Overview This DNS server provides: - **External DNS** for connectvm.cloud (public access) - **Multi-tenant DNS** for dev, prod, and QA teams - **High Availability** with 3 replicas - **Metrics** for monitoring ## ๐ŸŒ DNS Zones Configured ### 1. Main Domain: `connectvm.cloud` **Public DNS for main services** Available records: - `rancher.connectvm.cloud` โ†’ 160.30.114.10 - `paste.connectvm.cloud` โ†’ 160.30.114.10 - `fleet.connectvm.cloud` โ†’ 160.30.114.10 - `hello.connectvm.cloud` โ†’ 160.30.114.10 - `dns.connectvm.cloud` โ†’ 160.30.114.10 - `*.connectvm.cloud` โ†’ 160.30.114.10 (wildcard) ### 2. Dev Team: `dev.connectvm.cloud` **Development team's DNS zone** Available records: - `app1.dev.connectvm.cloud` - `app2.dev.connectvm.cloud` - `api.dev.connectvm.cloud` - `web.dev.connectvm.cloud` - `dashboard.dev.connectvm.cloud` - `jenkins.dev.connectvm.cloud` - `gitlab.dev.connectvm.cloud` - `db.dev.connectvm.cloud` - `redis.dev.connectvm.cloud` - `*.dev.connectvm.cloud` (wildcard) ### 3. Prod Team: `prod.connectvm.cloud` **Production team's DNS zone** Available records: - `api.prod.connectvm.cloud` - `web.prod.connectvm.cloud` - `app.prod.connectvm.cloud` - `admin.prod.connectvm.cloud` - `portal.prod.connectvm.cloud` - `db.prod.connectvm.cloud` - `monitoring.prod.connectvm.cloud` - `*.prod.connectvm.cloud` (wildcard) ### 4. QA Team: `qa.connectvm.cloud` **QA/Testing team's DNS zone** Available records: - `test.qa.connectvm.cloud` - `staging.qa.connectvm.cloud` - `selenium.qa.connectvm.cloud` - `automation.qa.connectvm.cloud` - `reports.qa.connectvm.cloud` - `*.qa.connectvm.cloud` (wildcard) ## ๐Ÿ”ง External Access ### DNS Server IPs: - **Primary**: `160.30.114.10:30053` (UDP/TCP) - **Internal**: `10.96.100.100:53` (ClusterIP) ### Configure Clients to Use DNS: **Linux/Mac:** ```bash # Add to /etc/resolv.conf nameserver 160.30.114.10 # Or use specific port with dig: dig @160.30.114.10 -p 30053 rancher.connectvm.cloud ``` **Windows:** ```powershell # Set DNS server netsh interface ip set dns "Ethernet" static 160.30.114.10 ``` **Kubernetes Pods:** ```yaml spec: dnsPolicy: None dnsConfig: nameservers: - 10.96.100.100 searches: - connectvm.cloud - dev.connectvm.cloud ``` ## ๐Ÿ“Š Monitoring Access DNS metrics: - **URL**: https://dns.connectvm.cloud/metrics - **Prometheus endpoint**: Port 9153 Metrics include: - Query count - Query types - Response codes - Cache hit/miss rates - Zone transfer stats ## ๐Ÿ”’ Security Features - **Zone isolation**: Each tenant has separate DNS zone - **No zone transfers**: Zones are read-only - **Query logging**: All queries are logged - **Rate limiting**: Built-in caching (300s TTL) ## ๐Ÿ› ๏ธ Management ### Add New Record: 1. Edit `dns-server.yaml` ConfigMap 2. Add record to appropriate zone file 3. Increment Serial number 4. Git push โ†’ Fleet auto-deploys **Example** - Add new dev app: ``` newapp IN A 160.30.114.10 ``` ### Add New Tenant Zone: 1. Create new zone file in ConfigMap 2. Add zone to Corefile 3. Git push ## ๐Ÿงช Testing Test DNS resolution: ```bash # Test main domain dig @160.30.114.10 -p 30053 rancher.connectvm.cloud # Test dev tenant dig @160.30.114.10 -p 30053 app1.dev.connectvm.cloud # Test prod tenant dig @160.30.114.10 -p 30053 api.prod.connectvm.cloud # Test QA tenant dig @160.30.114.10 -p 30053 test.qa.connectvm.cloud # Test wildcard dig @160.30.114.10 -p 30053 anything.dev.connectvm.cloud ``` ## ๐Ÿ“ฑ Use Cases ### For Dev Team: ```bash # Deploy app with custom DNS kubectl create deployment myapp --image=nginx kubectl expose deployment myapp --port=80 # Access via: myapp.dev.connectvm.cloud ``` ### For Prod Team: ```bash # Production API endpoint api.prod.connectvm.cloud โ†’ Production API server ``` ### For QA Team: ```bash # Automated testing selenium.qa.connectvm.cloud โ†’ Selenium Grid automation.qa.connectvm.cloud โ†’ Test Runner ``` ## ๐Ÿš€ High Availability - **3 replicas** across different nodes - **Anti-affinity** rules for pod distribution - **Auto-restart** on failure - **Health checks** every 10 seconds ## ๐Ÿ“ DNS Server Info - **Software**: CoreDNS 1.11.1 - **Protocol**: DNS (UDP/TCP port 53) - **Upstream**: Google DNS (8.8.8.8, 8.8.4.4) - **Cache TTL**: 300 seconds - **Zone TTL**: 3600 seconds (1 hour) ## ๐ŸŽฏ Architecture ``` External Queries (port 30053) โ†“ NodePort Service โ†“ DNS Pods (3 replicas) โ†“ โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”‚ Main Zone โ”‚ Dev Zone โ”‚ Prod Zone โ”‚ โ”‚ qa Zone โ”‚ K8s DNS โ”‚ Upstream โ”‚ โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ ``` ## ๐Ÿ”„ Updates All DNS updates happen via GitOps: 1. Edit zone files in Git 2. Push to Gitea 3. Fleet auto-deploys in ~15 seconds 4. DNS records updated automatically No manual DNS server management needed!