]> git.openstreetmap.org Git - dns.git/blob - src/openstreetmap.js
b8fa1d6455119754965205a73e1fa0b3c36cecb3
[dns.git] / src / openstreetmap.js
1 D(DOMAIN, REGISTRAR, DnsProvider(PROVIDER),
2
3   // Publish CAA records indicating that only letsencrypt and globalsign (Fastly) should issue certificates
4
5   CAA_BUILDER({
6     label: "@",
7     ttl: "1h",
8     iodef: "mailto:hostmaster@openstreetmap.org",
9     issue: [
10       "letsencrypt.org",
11       "globalsign.com",   // Used by Fastly for CDN certificates
12     ],
13     issuewild: [
14       "letsencrypt.org",
15       "globalsign.com",   // Used by Fastly for CDN certificates
16     ],
17   }),
18
19   // Mail service
20
21   MX("@", 10, QUALIFY("a.mx")),
22   MX("messages", 10, QUALIFY("a.mx")),
23   MX("noreply", 10, QUALIFY("a.mx")),
24   MX("otrs", 10, QUALIFY("a.mx")),
25   MX("community", 10, QUALIFY("a.mx")),
26   MX("supporting", 10, QUALIFY("a.mx")),
27
28   A("a.mx", IPV4["fafnir.he"]),
29   AAAA("a.mx", IPV6["fafnir.he"]),
30   A("mail", IPV4["fafnir.he"]),
31   AAAA("mail", IPV6["fafnir.he"]),
32   A("mta-sts", IPV4["fafnir.he"]),
33   AAAA("mta-sts", IPV6["fafnir.he"]),
34
35   // Publish SPF records indicating that only shenron sends mail
36
37   SPF_BUILDER({
38     label: "@",
39     parts: [
40       "v=spf1",
41       "ip4:184.104.226.98",         // fafnir ipv4 (he.net)
42       "ip6:2001:470:1:b3b::2",      // fafnir ipv6 (he.net)
43       "ip4:87.252.214.98",          // fafnir ipv4 (equinix)
44       "ip6:2001:4d78:fe03:1c::2",   // fafnir ipv6 (equinix)
45       "ip4:193.60.236.0/24",        // ucl external
46       "ip4:82.199.86.96/27",        // amsterdam external (equinix)
47       "ip6:2001:4d78:500:5e3::/64", // amsterdam external (equinix)
48       "ip4:87.252.214.96/27",       // dublin external (equinix)
49       "ip6:2001:4d78:fe03:1c::/64", // dublin external (equinix)
50       "ip4:184.104.179.128/27",     // amsterdam external (he.net)
51       "ip6:2001:470:1:fa1::/64",    // amsterdam external (he.net)
52       "ip4:184.104.226.96/27",      // dublin external (he.net)
53       "ip6:2001:470:1:b3b::/64",    // dublin external (he.net)
54       "mx",                         // safety net if we change mx
55       "-all"
56     ]
57   }),
58
59   SPF_BUILDER({
60     label: "messages",
61     parts: [
62       "v=spf1",
63       "ip4:184.104.226.98",         // fafnir ipv4 (he.net)
64       "ip6:2001:470:1:b3b::2",      // fafnir ipv6 (he.net)
65       "ip4:87.252.214.98",          // fafnir ipv4 (equinix)
66       "ip6:2001:4d78:fe03:1c::2",   // fafnir ipv6 (equinix)
67       "ip4:193.60.236.0/24",        // ucl external
68       "ip4:82.199.86.96/27",        // amsterdam external (equinix)
69       "ip6:2001:4d78:500:5e3::/64", // amsterdam external (equinix)
70       "ip4:87.252.214.96/27",       // dublin external (equinix)
71       "ip6:2001:4d78:fe03:1c::/64", // dublin external (equinix)
72       "ip4:184.104.179.128/27",     // amsterdam external (he.net)
73       "ip6:2001:470:1:fa1::/64",    // amsterdam external (he.net)
74       "ip4:184.104.226.96/27",      // dublin external (he.net)
75       "ip6:2001:470:1:b3b::/64",    // dublin external (he.net)
76       "mx",                         // safety net if we change mx
77       "-all"
78     ]
79   }),
80
81   SPF_BUILDER({
82     label: "noreply",
83     parts: [
84       "v=spf1",
85       "ip4:184.104.226.98",         // fafnir ipv4 (he.net)
86       "ip6:2001:470:1:b3b::2",      // fafnir ipv6 (he.net)
87       "ip4:87.252.214.98",          // fafnir ipv4 (equinix)
88       "ip6:2001:4d78:fe03:1c::2",   // fafnir ipv6 (equinix)
89       "ip4:193.60.236.0/24",        // ucl external
90       "ip4:82.199.86.96/27",        // amsterdam external (equinix)
91       "ip6:2001:4d78:500:5e3::/64", // amsterdam external (equinix)
92       "ip4:87.252.214.96/27",       // dublin external (equinix)
93       "ip6:2001:4d78:fe03:1c::/64", // dublin external (equinix)
94       "ip4:184.104.179.128/27",     // amsterdam external (he.net)
95       "ip6:2001:470:1:fa1::/64",    // amsterdam external (he.net)
96       "ip4:184.104.226.96/27",      // dublin external (he.net)
97       "ip6:2001:470:1:b3b::/64",    // dublin external (he.net)
98       "mx",                         // safety net if we change mx
99       "-all"
100     ]
101   }),
102
103   SPF_BUILDER({
104     label: "otrs",
105     parts: [
106       "v=spf1",
107       "ip4:184.104.226.98",         // fafnir ipv4 (he.net)
108       "ip6:2001:470:1:b3b::2",      // fafnir ipv6 (he.net)
109       "ip4:87.252.214.98",          // fafnir ipv4 (equinix)
110       "ip6:2001:4d78:fe03:1c::2",   // fafnir ipv6 (equinix)
111       "ip4:193.60.236.0/24",        // ucl external
112       "ip4:82.199.86.96/27",        // amsterdam external (equinix)
113       "ip6:2001:4d78:500:5e3::/64", // amsterdam external (equinix)
114       "ip4:87.252.214.96/27",       // dublin external (equinix)
115       "ip6:2001:4d78:fe03:1c::/64", // dublin external (equinix)
116       "ip4:184.104.179.128/27",     // amsterdam external (he.net)
117       "ip6:2001:470:1:fa1::/64",    // amsterdam external (he.net)
118       "ip4:184.104.226.96/27",      // dublin external (he.net)
119       "ip6:2001:470:1:b3b::/64",    // dublin external (he.net)
120       "mx",                         // safety net if we change mx
121       "-all"
122     ]
123   }),
124
125   SPF_BUILDER({
126     label: "community",
127     parts: [
128       "v=spf1",
129       "ip4:184.104.226.98",         // fafnir ipv4 (he.net)
130       "ip6:2001:470:1:b3b::2",      // fafnir ipv6 (he.net)
131       "ip4:87.252.214.98",          // fafnir ipv4 (equinix)
132       "ip6:2001:4d78:fe03:1c::2",   // fafnir ipv6 (equinix)
133       "ip4:193.60.236.0/24",        // ucl external
134       "ip4:82.199.86.96/27",        // amsterdam external (equinix)
135       "ip6:2001:4d78:500:5e3::/64", // amsterdam external (equinix)
136       "ip4:87.252.214.96/27",       // dublin external (equinix)
137       "ip6:2001:4d78:fe03:1c::/64", // dublin external (equinix)
138       "ip4:184.104.179.128/27",     // amsterdam external (he.net)
139       "ip6:2001:470:1:fa1::/64",    // amsterdam external (he.net)
140       "ip4:184.104.226.96/27",      // dublin external (he.net)
141       "ip6:2001:470:1:b3b::/64",    // dublin external (he.net)
142       "mx",                         // safety net if we change mx
143       "-all"
144     ]
145   }),
146
147   SPF_BUILDER({
148     label: "supporting",
149     parts: [
150       "v=spf1",
151       "ip4:184.104.226.98",         // fafnir ipv4 (he.net)
152       "ip6:2001:470:1:b3b::2",      // fafnir ipv6 (he.net)
153       "ip4:87.252.214.98",          // fafnir ipv4 (equinix)
154       "ip6:2001:4d78:fe03:1c::2",   // fafnir ipv6 (equinix)
155       "ip4:193.60.236.0/24",        // ucl external
156       "ip4:82.199.86.96/27",        // amsterdam external (equinix)
157       "ip6:2001:4d78:500:5e3::/64", // amsterdam external (equinix)
158       "ip4:87.252.214.96/27",       // dublin external (equinix)
159       "ip6:2001:4d78:fe03:1c::/64", // dublin external (equinix)
160       "ip4:184.104.179.128/27",     // amsterdam external (he.net)
161       "ip6:2001:470:1:fa1::/64",    // amsterdam external (he.net)
162       "ip4:184.104.226.96/27",      // dublin external (he.net)
163       "ip6:2001:470:1:b3b::/64",    // dublin external (he.net)
164       "mx",                         // safety net if we change mx
165       "-all"
166     ]
167   }),
168
169   // Publish DKIM public key
170
171   TXT("20200301._domainkey", "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzvoNZVOGfw1V4A171hxHMhzVTAnIUQVJ8iX3wbqCld8A5iIaXeTGYvBmewymax/cYJS4QqzbpUzkgrrTA9avuZhd+QGJDgjADgx4VyMOaOS6FwAxS0uXtLrt+lsixRDx/feKyZHaxjzJAQy46ok77xXL4UXIaaovw6G6eZpIScMzZQ2zkKNJxTICzzSOduIilHhMWte4XP+/2PdRmD7Ge9jb0U4bZjswX0AqKSGzDKYw+yxVna9l53adeCnklqg2ofoXu+ResiH+kt05aCUOMo8en3em6yBnRCMalgi1E3Tt7I5BWcYFRkT/8agUGW4gGC6XMV9IskOsYL0emG0kGwIDAQAB", AUTOSPLIT),
172
173   // Publish DMARC report-only policy
174
175   DMARC_BUILDER({
176     policy: "none",
177     rua: [
178       "mailto:openstreetmap-d@dmarc.report-uri.com"
179     ],
180     failureOptions: 1
181   }),
182
183   // Announce MTA-STS policy and TLSRPT policy for error reports
184
185   TXT("_mta-sts", "v=STSv1; id=202001291805Z"),
186   TXT("_smtp._tls", "v=TLSRPTv1; rua=mailto:openstreetmap-d@tlsrpt.report-uri.com"),
187
188   // Fastly cert domain ownership confirmation
189
190   TXT("@", "_globalsign-domain-verification=ps00GlW1BzY9c2_cwH_pFqRkvzZyaCVZ-3RLssRG6S"),
191   TXT("@", "_globalsign-domain-verification=W0buKB5ZmL-VwwHw2oQyQImk3I1q3hSemf2qmB1hjP"),
192
193   // Facebook Business domain verification
194
195   TXT("@", "facebook-domain-verification=j5hix5i8r0kortfugqf2p9wx9x9by0"),
196
197   // Bluesky domain verification
198
199   TXT("_atproto", "did=did:plc:i6llv7iwybeipknl57v4dalb"),
200
201   // Delegate MTA-STS policy for subdomains
202
203   CNAME("_mta-sts.messages", QUALIFY("_mta-sts")),
204   CNAME("_mta-sts.noreply", QUALIFY("_mta-sts")),
205   CNAME("_mta-sts.otrs", QUALIFY("_mta-sts")),
206   CNAME("_mta-sts.community", QUALIFY("_mta-sts")),
207   CNAME("_mta-sts.supporting", QUALIFY("_mta-sts")),
208
209   // Google postmaster tools verification
210
211   CNAME("af323lytato5", "gv-o4v3qh5pfayqex.dv.googlehosted.com."),
212   CNAME("irzdddnmh465", "gv-cwr6bvt7xsgact.dv.googlehosted.com."),
213
214   // Main web servers and their aliases
215
216   A("spike-01", IPV4["spike-01.he"]),
217   AAAA("spike-01", IPV6["spike-01.he"]),
218   // A("@", IPV4["spike-01.he"]),
219   // AAAA("@", IPV6["spike-01.he"]),
220   // A("www", IPV4["spike-01.he"]),
221   // AAAA("www", IPV6["spike-01.he"]),
222   // A("api", IPV4["spike-01.he"]),
223   // AAAA("api", IPV6["spike-01.he"]),
224   // A("maps", IPV4["spike-01.he"]),
225   // AAAA("maps", IPV6["spike-01.he"]),
226   // A("mapz", IPV4["spike-01.he"]),
227   // AAAA("mapz", IPV6["spike-01.he"]),
228   A("spike-01.dub", IPV4["spike-01.dub"]),
229   A("spike-01.oob", IPV4["spike-01.oob"]),
230
231   A("spike-02", IPV4["spike-02.he"]),
232   AAAA("spike-02", IPV6["spike-02.he"]),
233   // A("@", IPV4["spike-02.he"]),
234   // AAAA("@", IPV6["spike-02.he"]),
235   // A("www", IPV4["spike-02.he"]),
236   // AAAA("www", IPV6["spike-02.he"]),
237   // A("api", IPV4["spike-02.he"]),
238   // AAAA("api", IPV6["spike-02.he"]),
239   // A("maps", IPV4["spike-02.he"]),
240   // AAAA("maps", IPV6["spike-02.he"]),
241   // A("mapz", IPV4["spike-02.he"]),
242   // AAAA("mapz", IPV6["spike-02.he"]),
243   A("spike-02.dub", IPV4["spike-02.dub"]),
244   A("spike-02.oob", IPV4["spike-02.oob"]),
245
246   A("spike-03", IPV4["spike-03.he"]),
247   AAAA("spike-03", IPV6["spike-03.he"]),
248   // A("@", IPV4["spike-03.he"]),
249   // AAAA("@", IPV6["spike-03.he"]),
250   // A("www", IPV4["spike-03.he"]),
251   // AAAA("www", IPV6["spike-03.he"]),
252   // A("api", IPV4["spike-03.he"]),
253   // AAAA("api", IPV6["spike-03.he"]),
254   // A("maps", IPV4["spike-03.he"]),
255   // AAAA("maps", IPV6["spike-03.he"]),
256   // A("mapz", IPV4["spike-03.he"]),
257   // AAAA("mapz", IPV6["spike-03.he"]),
258   A("spike-03.dub", IPV4["spike-03.dub"]),
259   A("spike-03.oob", IPV4["spike-03.oob"]),
260
261   A("spike-06", IPV4["spike-06"]),
262   AAAA("spike-06", IPV6["spike-06"]),
263   A("@", IPV4["spike-06"], CF_PROXY_ON),
264   AAAA("@", IPV6["spike-06"], CF_PROXY_ON),
265   A("www", IPV4["spike-06"], CF_PROXY_ON),
266   AAAA("www", IPV6["spike-06"], CF_PROXY_ON),
267   A("api", IPV4["spike-06"], CF_PROXY_ON),
268   AAAA("api", IPV6["spike-06"], CF_PROXY_ON),
269   A("maps", IPV4["spike-06"], CF_PROXY_ON),
270   AAAA("maps", IPV6["spike-06"], CF_PROXY_ON),
271   A("mapz", IPV4["spike-06"], CF_PROXY_ON),
272   AAAA("mapz", IPV6["spike-06"], CF_PROXY_ON),
273   A("spike-06.ams", IPV4["spike-06.ams"]),
274   A("spike-06.oob", IPV4["spike-06.oob"]),
275
276   A("spike-07", IPV4["spike-07"]),
277   AAAA("spike-07", IPV6["spike-07"]),
278   A("@", IPV4["spike-07"], CF_PROXY_ON),
279   AAAA("@", IPV6["spike-07"], CF_PROXY_ON),
280   A("www", IPV4["spike-07"], CF_PROXY_ON),
281   AAAA("www", IPV6["spike-07"], CF_PROXY_ON),
282   A("api", IPV4["spike-07"], CF_PROXY_ON),
283   AAAA("api", IPV6["spike-07"], CF_PROXY_ON),
284   A("maps", IPV4["spike-07"], CF_PROXY_ON),
285   AAAA("maps", IPV6["spike-07"], CF_PROXY_ON),
286   A("mapz", IPV4["spike-07"], CF_PROXY_ON),
287   AAAA("mapz", IPV6["spike-07"], CF_PROXY_ON),
288   A("spike-07.ams", IPV4["spike-07.ams"]),
289   A("spike-07.oob", IPV4["spike-07.oob"]),
290
291   A("spike-08", IPV4["spike-08"]),
292   AAAA("spike-08", IPV6["spike-08"]),
293   A("@", IPV4["spike-08"], CF_PROXY_ON),
294   AAAA("@", IPV6["spike-08"], CF_PROXY_ON),
295   A("www", IPV4["spike-08"], CF_PROXY_ON),
296   AAAA("www", IPV6["spike-08"], CF_PROXY_ON),
297   A("api", IPV4["spike-08"], CF_PROXY_ON),
298   AAAA("api", IPV6["spike-08"], CF_PROXY_ON),
299   A("maps", IPV4["spike-08"], CF_PROXY_ON),
300   AAAA("maps", IPV6["spike-08"], CF_PROXY_ON),
301   A("mapz", IPV4["spike-08"], CF_PROXY_ON),
302   AAAA("mapz", IPV6["spike-08"], CF_PROXY_ON),
303   A("spike-08.ams", IPV4["spike-08.ams"]),
304   A("spike-08.oob", IPV4["spike-08.oob"]),
305
306   // HTTPS / SVCB records
307   HTTPS("www", 1, ".", "alpn=h2"),
308   HTTPS("api", 1, ".", "alpn=h2"),
309   HTTPS("maps", 1, ".", "alpn=h2"),
310   HTTPS("mapz", 1, ".", "alpn=h2"),
311
312   // Nominatim servers
313
314   A("dulcy", IPV4["dulcy"]),
315   AAAA("dulcy", IPV6["dulcy"]),
316   A("dulcy.ams", IPV4["dulcy.ams"]),
317   A("dulcy.oob", IPV4["dulcy.oob"]),
318
319   A("longma", IPV4["longma.he"]),
320   AAAA("longma", IPV6["longma.he"]),
321   A("longma.dub", IPV4["longma.dub"]),
322   A("longma.oob", IPV4["longma.oob"]),
323
324   A("stormfly-04", IPV4["stormfly-04"]),
325   AAAA("stormfly-04", IPV6["stormfly-04"]),
326   A("stormfly-04.oob", IPV4["stormfly-04.oob"]),
327
328   A("vhagar", IPV4["vhagar"]),
329   AAAA("vhagar", IPV6["vhagar"]),
330   A("vhagar.ams", IPV4["vhagar.ams"]),
331   A("vhagar.oob", IPV4["vhagar.oob"]),
332
333   CNAME("nominatim", "nominatim.geo.openstreetmap.org."),
334   CNAME("qgis.nominatim", "nominatim.geo.openstreetmap.org."),
335   CNAME("qa-tile.nominatim", "longma.openstreetmap.org."),
336
337   // Tile servers
338
339   A("odin", IPV4["odin"]),
340   AAAA("odin", IPV6["odin"]),
341   A("odin.ams", IPV4["odin.ams"]),
342   A("odin.oob", IPV4["odin.oob"]),
343
344   A("ysera", IPV4["ysera"]),
345   A("ysera.ucl", IPV4["ysera.ucl"]),
346   A("ysera.oob", IPV4["ysera.oob"]),
347
348   A("culebre", IPV4["culebre.he"]),
349   AAAA("culebre", IPV6["culebre.he"]),
350   A("culebre.dub", IPV4["culebre.dub"]),
351   A("culebre.oob", IPV4["culebre.oob"]),
352
353   A("nidhogg", IPV4["nidhogg"]),
354   AAAA("nidhogg", IPV6["nidhogg"]),
355   A("nidhogg.oob", IPV4["nidhogg.oob"]),
356
357   A("wawel", IPV4["wawel"]),
358
359   A("rhaegal", IPV4["rhaegal"]),
360   AAAA("rhaegal", IPV6["rhaegal"]),
361
362   A("palulukon", IPV4["palulukon"]),
363
364   A("piasa", IPV4["piasa"]),
365   AAAA("piasa", IPV6["piasa"]),
366   A("piasa.oob", IPV4["piasa.oob"]),
367
368   A("albi", IPV4["albi"]),
369   AAAA("albi", IPV6["albi"]),
370
371   CNAME("tile", "dualstack.n.sni.global.fastly.net."),
372   CNAME("a.tile", "dualstack.n.sni.global.fastly.net."),
373   CNAME("b.tile", "dualstack.n.sni.global.fastly.net."),
374   CNAME("c.tile", "dualstack.n.sni.global.fastly.net."),
375
376   A("render", IPV4["culebre.he"]),
377   A("render", IPV4["nidhogg"]),
378   AAAA("render", IPV6["culebre.he"]),
379   AAAA("render", IPV6["nidhogg"]),
380
381   // Vector tile servers
382
383   A("cmok", IPV4["cmok"]),
384
385   A("dribble", IPV4["dribble"]),
386   AAAA("dribble", IPV6["dribble"]),
387   A("dribble.ams", IPV4["dribble.ams"]),
388   A("dribble.oob", IPV4["dribble.oob"]),
389
390   CNAME("vector", "dualstack.n.sni.global.fastly.net."),
391
392   // Site gateways
393
394   A("fafnir", IPV4["fafnir.he"]),
395   AAAA("fafnir", IPV6["fafnir.he"]),
396   A("fafnir.dub", IPV4["fafnir.dub"]),
397   A("fafnir.oob", IPV4["fafnir.oob"]),
398
399   // Planet servers
400
401   A("norbert", IPV4["norbert"]),
402   AAAA("norbert", IPV6["norbert"]),
403   A("backup", IPV4["norbert"]),
404   AAAA("backup", IPV6["norbert"]),
405   A("planet", IPV4["norbert"]),
406   AAAA("planet", IPV6["norbert"]),
407   A("norbert.ams", IPV4["norbert.ams"]),
408   A("norbert.oob", IPV4["norbert.oob"]),
409
410   // HTTPS / SVCB records
411   HTTPS("planet", 1, ".", "alpn=h2"),
412
413   A("horntail", IPV4["horntail.he"]),
414   AAAA("horntail", IPV6["horntail.he"]),
415   // A("backup", IPV4["horntail.he"]),
416   // AAAA("backup", IPV6["horntail.he"]),
417   // A("planet", IPV4["horntail.he"]),
418   // AAAA("planet", IPV6["horntail.he"]),
419   A("horntail.dub", IPV4["horntail.dub"]),
420   A("horntail.oob", IPV4["horntail.oob"]),
421
422   // Database servers
423
424   A("snap-01.ams", IPV4["snap-01.ams"]),
425   A("snap-01.oob", IPV4["snap-01.oob"]),
426
427   A("snap-02.ucl", IPV4["snap-02.ucl"]),
428   A("snap-02.oob", IPV4["snap-02.oob"]),
429
430   A("snap-03.dub", IPV4["snap-03.dub"]),
431   A("snap-03.oob", IPV4["snap-03.oob"]),
432
433   A("karm.ams", IPV4["karm.ams"]),
434   A("karm.oob", IPV4["karm.oob"]),
435
436   A("eddie.ucl", IPV4["eddie.ucl"]),
437   A("eddie.oob", IPV4["eddie.oob"]),
438
439   // Development server with wildcard alias for user sites
440
441   A("faffy", IPV4["faffy"]),
442   AAAA("faffy", IPV6["faffy"]),
443   A("dev", IPV4["faffy"]),
444   AAAA("dev", IPV6["faffy"]),
445   A("*.dev", IPV4["faffy"]),
446   AAAA("*.dev", IPV6["faffy"]),
447   A("ooc", IPV4["faffy"]),
448   AAAA("ooc", IPV6["faffy"]),
449   A("a.ooc", IPV4["faffy"]),
450   AAAA("a.ooc", IPV6["faffy"]),
451   A("b.ooc", IPV4["faffy"]),
452   AAAA("b.ooc", IPV6["faffy"]),
453   A("c.ooc", IPV4["faffy"]),
454   AAAA("c.ooc", IPV6["faffy"]),
455   A("npe", IPV4["faffy"]),
456   AAAA("npe", IPV6["faffy"]),
457   A("faffy.ams", IPV4["faffy.ams"]),
458   A("faffy.oob", IPV4["faffy.oob"]),
459
460   // Foundation server
461
462   A("ridley", IPV4["ridley"]),
463   A("blog", IPV4["ridley"]),
464   A("foundation", IPV4["ridley"]),
465   A("ridley.ucl", IPV4["ridley.ucl"]),
466   A("ridley.oob", IPV4["ridley.oob"]),
467
468   // HTTPS / SVCB records
469   HTTPS("blog", 1, ".", "alpn=h2"),
470   HTTPS("foundation", 1, ".", "alpn=h2"),
471
472   // Matomo server
473
474   A("smaug", IPV4["smaug.he"]),
475   AAAA("smaug", IPV6["smaug.he"]),
476   A("matomo", IPV4["smaug.he"]),
477   AAAA("matomo", IPV6["smaug.he"]),
478   A("piwik", IPV4["smaug.he"]),
479   AAAA("piwik", IPV6["smaug.he"]),
480   A("smaug.dub", IPV4["smaug.dub"]),
481   A("smaug.oob", IPV4["smaug.oob"]),
482
483   // HTTPS / SVCB records
484   HTTPS("matomo", 1, ".", "alpn=h2"),
485   HTTPS("piwik", 1, ".", "alpn=h2"),
486
487   // Imagery servers
488
489   A("agri", IPV4["lockheed"]),
490   AAAA("agri", IPV6["lockheed"]),
491   A("a.agri", IPV4["lockheed"]),
492   AAAA("a.agri", IPV6["lockheed"]),
493   A("b.agri", IPV4["lockheed"]),
494   AAAA("b.agri", IPV6["lockheed"]),
495   A("c.agri", IPV4["lockheed"]),
496   AAAA("c.agri", IPV6["lockheed"]),
497
498   // HTTPS / SVCB records
499   HTTPS("agri", 1, ".", "alpn=h2"),
500   HTTPS("a.agri", 1, ".", "alpn=h2"),
501   HTTPS("b.agri", 1, ".", "alpn=h2"),
502   HTTPS("c.agri", 1, ".", "alpn=h2"),
503
504   A("os", IPV4["lockheed"]),
505   AAAA("os", IPV6["lockheed"]),
506   A("a.os", IPV4["lockheed"]),
507   AAAA("a.os", IPV6["lockheed"]),
508   A("b.os", IPV4["lockheed"]),
509   AAAA("b.os", IPV6["lockheed"]),
510   A("c.os", IPV4["lockheed"]),
511   AAAA("c.os", IPV6["lockheed"]),
512
513   // HTTPS / SVCB records
514   HTTPS("os", 1, ".", "alpn=h2"),
515   HTTPS("a.os", 1, ".", "alpn=h2"),
516   HTTPS("b.os", 1, ".", "alpn=h2"),
517   HTTPS("c.os", 1, ".", "alpn=h2"),
518
519
520   // Prometheus server and munin redirect
521
522   A("stormfly-03", IPV4["stormfly-03"]),
523   AAAA("stormfly-03", IPV6["stormfly-03"]),
524   A("prometheus", IPV4["stormfly-03"]),
525   AAAA("prometheus", IPV6["stormfly-03"]),
526   A("munin", IPV4["stormfly-03"]),
527   AAAA("munin", IPV6["stormfly-03"]),
528   A("stormfly-03.oob", IPV4["stormfly-03.oob"]),
529
530   // HTTPS / SVCB records
531   HTTPS("prometheus", 1, ".", "alpn=h2"),
532   HTTPS("munin", 1, ".", "alpn=h2"),
533
534   // Management server
535
536   A("idris", IPV4["idris.he"]),
537   AAAA("idris", IPV6["idris.he"]),
538   A("acme", IPV4["idris.he"]),
539   AAAA("acme", IPV6["idris.he"]),
540   A("apt", IPV4["idris.he"]),
541   AAAA("apt", IPV6["idris.he"]),
542   A("chef", IPV4["idris.he"]),
543   AAAA("chef", IPV6["idris.he"]),
544   A("dns", IPV4["idris.he"]),
545   AAAA("dns", IPV6["idris.he"]),
546   A("git", IPV4["idris.he"]),
547   AAAA("git", IPV6["idris.he"]),
548   A("hardware", IPV4["idris.he"]),
549   AAAA("hardware", IPV6["idris.he"]),
550   A("idris.dub", IPV4["idris.dub"]),
551   A("idris.oob", IPV4["idris.oob"]),
552
553   // HTTPS / SVCB records
554   HTTPS("acme", 1, ".", "alpn=h2"),
555   HTTPS("chef", 1, ".", "alpn=h2"),
556   HTTPS("dns", 1, ".", "alpn=h2"),
557   HTTPS("git", 1, ".", "alpn=h2"),
558   HTTPS("hardware", 1, ".", "alpn=h2"),
559
560   // Managed network switches
561
562   A("switch1.ams", IPV4["switch1.ams"]),
563   AAAA("switch1.ams", IPV6["switch1.ams"]),
564
565   A("switch1.dub", IPV4["switch1.he.dub"]),
566   AAAA("switch1.dub", IPV6["switch1.he.dub"]),
567
568   // Managed power strips
569
570   A("pdu1.ams", IPV4["pdu1.ams"]),
571   A("pdu2.ams", IPV4["pdu2.ams"]),
572
573   A("pdu1.dub", IPV4["pdu1.dub"]),
574   A("pdu2.dub", IPV4["pdu2.dub"]),
575
576   // Out of band access servers
577
578   A("oob1.ams", IPV4["oob1.ams"]),
579
580   A("oob1.dub", IPV4["oob1.dub"]),
581
582   // Network gateways
583
584   A("equinix-gw.ams", IPV4["equinix-gw.ams"]),
585   AAAA("equinix-gw.ams", IPV6["equinix-gw.ams"]),
586   A("equinix-gw-1.ams", IPV4["equinix-gw-1.ams"]),
587   AAAA("equinix-gw-1.ams", IPV6["equinix-gw-1.ams"]),
588   A("equinix-gw-2.ams", IPV4["equinix-gw-2.ams"]),
589   AAAA("equinix-gw-2.ams", IPV6["equinix-gw-2.ams"]),
590   A("equinix-osm.ams", IPV4["equinix-osm.ams"]),
591   AAAA("equinix-osm.ams", IPV6["equinix-osm.ams"]),
592
593   A("equinix-gw.dub", IPV4["equinix-gw.dub"]),
594   AAAA("equinix-gw.dub", IPV6["equinix-gw.dub"]),
595   A("equinix-gw-1.dub", IPV4["equinix-gw-1.dub"]),
596   AAAA("equinix-gw-1.dub", IPV6["equinix-gw-1.dub"]),
597   A("equinix-gw-2.dub", IPV4["equinix-gw-2.dub"]),
598   AAAA("equinix-gw-2.dub", IPV6["equinix-gw-2.dub"]),
599   A("equinix-osm.dub", IPV4["equinix-osm.dub"]),
600   AAAA("equinix-osm.dub", IPV6["equinix-osm.dub"]),
601
602   // Bytemark machine, and the services which operate from it
603
604   A("shenron", IPV4["shenron"]),
605   AAAA("shenron", IPV6["shenron"]),
606   A("lists", IPV4["shenron"]),
607   AAAA("lists", IPV6["shenron"]),
608   A("help", IPV4["shenron"]),
609   AAAA("help", IPV6["shenron"]),
610
611   // HTTPS / SVCB records
612   HTTPS("lists", 1, ".", "alpn=h2"),
613   HTTPS("help", 1, ".", "alpn=h2"),
614
615   // Naga service
616
617   A("naga", IPV4["naga.he"]),
618   AAAA("naga", IPV6["naga.he"]),
619   A("svn", IPV4["naga.he"]),
620   AAAA("svn", IPV6["naga.he"]),
621   A("trac", IPV4["naga.he"]),
622   AAAA("trac", IPV6["naga.he"]),
623   A("irc", IPV4["naga.he"]),
624   AAAA("irc", IPV6["naga.he"]),
625   A("blogs", IPV4["naga.he"]),
626   AAAA("blogs", IPV6["naga.he"]),
627   A("welcome", IPV4["naga.he"]),
628   AAAA("welcome", IPV6["naga.he"]),
629   A("operations", IPV4["naga.he"]),
630   AAAA("operations", IPV6["naga.he"]),
631   A("hot", IPV4["naga.he"]),
632   AAAA("hot", IPV6["naga.he"]),
633   A("dmca", IPV4["naga.he"]),
634   AAAA("dmca", IPV6["naga.he"]),
635   A("otrs", IPV4["naga.he"]),
636   AAAA("otrs", IPV6["naga.he"]),
637   A("birthday20", IPV4["naga.he"]),
638   AAAA("birthday20", IPV6["naga.he"]),
639
640   // HTTPS / SVCB records
641   HTTPS("svn", 1, ".", "alpn=h2"),
642   HTTPS("trac", 1, ".", "alpn=h2"),
643   HTTPS("irc", 1, ".", "alpn=h2"),
644   HTTPS("blogs", 1, ".", "alpn=h2"),
645   HTTPS("welcome", 1, ".", "alpn=h2"),
646   HTTPS("operations", 1, ".", "alpn=h2"),
647   HTTPS("hot", 1, ".", "alpn=h2"),
648   HTTPS("dmca", 1, ".", "alpn=h2"),
649   // HTTPS("otrs", 1, ".", "alpn=h2"), - OTRS is not available using HTTPS/2
650   HTTPS("birthday20", 1, ".", "alpn=h2"),
651
652   A("naga.dub", IPV4["naga.dub"]),
653   A("naga.oob", IPV4["naga.oob"]),
654
655   // Wiki servers
656
657   A("konqi", IPV4["konqi.he"]),
658   AAAA("konqi", IPV6["konqi.he"]),
659   A("wiki", IPV4["konqi.he"]),
660   AAAA("wiki", IPV6["konqi.he"]),
661   A("konqi.dub", IPV4["konqi.dub"]),
662   A("konqi.oob", IPV4["konqi.oob"]),
663
664   // HTTPS / SVCB records
665   HTTPS("wiki", 1, ".", "alpn=h2"),
666
667   // Overpass server
668
669   A("grisu", IPV4["grisu.he"]),
670   AAAA("grisu", IPV6["grisu.he"]),
671   A("query", IPV4["grisu.he"]),
672   AAAA("query", IPV6["grisu.he"]),
673   A("grisu.dub", IPV4["grisu.dub"]),
674   A("grisu.oob", IPV4["grisu.oob"]),
675
676   // HTTPS / SVCB records
677   HTTPS("query", 1, ".", "alpn=h2"),
678
679   // GPS tile server
680
681   A("muirdris", IPV4["muirdris.he"]),
682   AAAA("muirdris", IPV6["muirdris.he"]),
683   A("gps-tile", IPV4["muirdris.he"]),
684   AAAA("gps-tile", IPV6["muirdris.he"]),
685   A("a.gps-tile", IPV4["muirdris.he"]),
686   AAAA("a.gps-tile", IPV6["muirdris.he"]),
687   A("b.gps-tile", IPV4["muirdris.he"]),
688   AAAA("b.gps-tile", IPV6["muirdris.he"]),
689   A("c.gps-tile", IPV4["muirdris.he"]),
690   AAAA("c.gps-tile", IPV6["muirdris.he"]),
691   A("gps.tile", IPV4["muirdris.he"]),
692   AAAA("gps.tile", IPV6["muirdris.he"]),
693   A("gps-a.tile", IPV4["muirdris.he"]),
694   AAAA("gps-a.tile", IPV6["muirdris.he"]),
695   A("gps-b.tile", IPV4["muirdris.he"]),
696   AAAA("gps-b.tile", IPV6["muirdris.he"]),
697   A("gps-c.tile", IPV4["muirdris.he"]),
698   AAAA("gps-c.tile", IPV6["muirdris.he"]),
699   A("muirdris.dub", IPV4["muirdris.dub"]),
700   A("muirdris.oob", IPV4["muirdris.oob"]),
701
702   // HTTPS / SVCB records
703   HTTPS("gps-tile", 1, ".", "alpn=h2"),
704   HTTPS("a.gps-tile", 1, ".", "alpn=h2"),
705   HTTPS("b.gps-tile", 1, ".", "alpn=h2"),
706   HTTPS("c.gps-tile", 1, ".", "alpn=h2"),
707   HTTPS("gps-a.tile", 1, ".", "alpn=h2"),
708   HTTPS("gps-b.tile", 1, ".", "alpn=h2"),
709   HTTPS("gps-c.tile", 1, ".", "alpn=h2"),
710
711   // Tile cache servers
712
713   A("ridgeback", IPV4["ridgeback"]),
714   A("ridgeback.oob", IPV4["ridgeback.oob"]),
715   A("angor", IPV4["angor"]),
716   AAAA("angor", IPV6["angor"]),
717   A("ladon", IPV4["ladon"]),
718   AAAA("ladon", IPV6["ladon"]),
719   A("neak", IPV4["neak"]),
720   A("meraxes", IPV4["meraxes"]),
721   AAAA("meraxes", IPV6["meraxes"]),
722
723   // Donation site and new OSMF crm site
724
725   A("donate", IPV4["ridley"]),
726   A("support", IPV4["ridley"]),
727   A("supporting", IPV4["ridley"]),
728
729   // HTTPS / SVCB records
730   HTTPS("donate", 1, ".", "alpn=h2"),
731   HTTPS("support", 1, ".", "alpn=h2"),
732   HTTPS("supporting", 1, ".", "alpn=h2"),
733
734   A("lockheed", IPV4["lockheed"]),
735   AAAA("lockheed", IPV6["lockheed"]),
736   A("lockheed.ams", IPV4["lockheed.ams"]),
737   A("lockheed.oob", IPV4["lockheed.oob"]),
738   A("tiler", IPV4["lockheed"]),
739   AAAA("tiler", IPV6["lockheed"]),
740   A("us-imagery", IPV4["lockheed"]),
741   AAAA("us-imagery", IPV6["lockheed"]),
742   A("a.us-imagery", IPV4["lockheed"]),
743   AAAA("a.us-imagery", IPV6["lockheed"]),
744   A("b.us-imagery", IPV4["lockheed"]),
745   AAAA("b.us-imagery", IPV6["lockheed"]),
746   A("c.us-imagery", IPV4["lockheed"]),
747   AAAA("c.us-imagery", IPV6["lockheed"]),
748
749   // HTTPS / SVCB records
750   HTTPS("tiler", 1, ".", "alpn=h2"),
751   HTTPS("us-imagery", 1, ".", "alpn=h2"),
752   HTTPS("a.us-imagery", 1, ".", "alpn=h2"),
753   HTTPS("b.us-imagery", 1, ".", "alpn=h2"),
754   HTTPS("c.us-imagery", 1, ".", "alpn=h2"),
755
756   // Discourse server ("community")
757
758   A("fume", IPV4["fume.he"]),
759   AAAA("fume", IPV6["fume.he"]),
760   A("fume.dub", IPV4["fume.dub"]),
761   A("fume.oob", IPV4["fume.oob"]),
762
763   A("community", IPV4["fume.he"]),
764   A("communities", IPV4["fume.he"]),
765   A("c", IPV4["fume.he"]),
766   AAAA("community", IPV6["fume.he"]),
767   AAAA("communities", IPV6["fume.he"]),
768   AAAA("c", IPV6["fume.he"]),
769
770   // HTTPS / SVCB records
771   HTTPS("community", 1, ".", "alpn=h2"),
772   HTTPS("communities", 1, ".", "alpn=h2"),
773   HTTPS("c", 1, ".", "alpn=h2"),
774
775   CNAME("community-cdn", "dualstack.n.sni.global.fastly.net."),
776   TXT("community", "google-site-verification=hQ8GZyj4KwnPqAX2oAzpbLrh6I5dfR08PSdL3icVkfg"),
777
778   A("forum", IPV4["fume.he"]),
779   AAAA("forum", IPV6["fume.he"]),
780
781   // HTTPS / SVCB records
782   HTTPS("forum", 1, ".", "alpn=h2"),
783
784   // Taginfo and Staging Blog Server
785
786   A("tabaluga", IPV4["tabaluga"]),
787   AAAA("tabaluga", IPV6["tabaluga"]),
788   A("tabaluga.ams", IPV4["tabaluga.ams"]),
789   A("tabaluga.oob", IPV4["tabaluga.oob"]),
790
791   A("staging.blog", IPV4["tabaluga"]),
792   AAAA("staging.blog", IPV6["tabaluga"]),
793
794   // HTTPS / SVCB records
795   HTTPS("staging.blog", 1, ".", "alpn=h2"),
796
797   A("taginfo", IPV4["tabaluga"]),
798   AAAA("taginfo", IPV6["tabaluga"]),
799
800   // HTTPS / SVCB records
801   HTTPS("taginfo", 1, ".", "alpn=h2"),
802
803   // Spare servers
804
805
806   // Uptime site at StatusCake
807
808   CNAME("uptime", "uptimessl-new.statuscake.com.")
809
810 );