GOV.UK for example uses both aws and gcp for DNS
But then, the cached values from AWS take a while to clear, TTL never seems to be applied properly. It always feels like the worst case in such a scenario is you can point everyone at the right thing within 24 hours.
(I don't know if this is how it works, but I thibk that's how it supposed to work)
Of course that requires the server to properly fail, i.e. stop responding to requests. That doesn't seem to be the case here
https://github.com/octodns/octodns
DNS is fastest first* rather than main/failover. If AWS DNS was down your GCP DNS would have replied (if all is well) sooner than {timeout} so your visitor would still have a response
* Sort of. I think if the client doesn't get a reply from the server it picked randomly in 1s they move on to the next server, repeat until all fail
What I'm a bit surprised / unsure of is what happens when I run "dig ns gov.uk". The results are:
gov.uk. 21559 IN NS ns1.surfnet.nl.
gov.uk. 21559 IN NS auth50.ns.de.uu.net.
gov.uk. 21559 IN NS ns3.ja.net.
gov.uk. 21559 IN NS ns2.ja.net.
gov.uk. 21559 IN NS ns0.ja.net.
gov.uk. 21559 IN NS auth00.ns.de.uu.net.
gov.uk. 21559 IN NS ns4.ja.net.
Who is ja.net , uu.net and surfnet.nl ..?EDIT: I see that ja.net i.e. jisc.ac.uk "manages the second level domain .gov.uk" -- https://www.jisc.ac.uk/domain-registry . I imagine that uu.net and surfnet.nl are there for redundancy
whois ja.net
Domain Name: JA.NET
Registry Domain ID: 499794_DOMAIN_NET-VRSN
Registrar WHOIS Server: whois.demys.com
Registrar URL: http://www.demys.com
"Demys is a leading provider of corporate domain name management and an ICANN accredited registrar" whois uu.net
Domain Name: UU.NET
Registry Domain ID: 5486163_DOMAIN_NET-VRSN
Registrar WHOIS Server: whois.markmonitor.com
surfnet is just an ISP in NetherlandsIs it possible to see if/where is gov.uk using GCP or AWS for its domain zones? From what I can see -- that's not the case? Or am I looking in the wrong place?
$ dig NS service.gov.uk +short
ns-cloud-e4.googledomains.com.
ns-cloud-e3.googledomains.com.
ns-cloud-e2.googledomains.com.
ns-cloud-e1.googledomains.com.
ns-831.awsdns-39.net.
ns-1983.awsdns-55.co.uk.
ns-117.awsdns-14.com.
ns-1080.awsdns-07.org.Problems starts when you want to easy make frequent changes and introduce complex software to manage DNS zones (and complexity usually comes with bugs).
The whole reason it takes a domain 24h to fully work with DNS is because it propagates the information other DNS servers, thus making not be a centralized service.
Relatively short TTLs are ubiquitous these days though.
https://namebase.io is a "registrar" for it.
https://learn.namebase.io/starting-from-zero/how-to-get-a-na...
This is so convoluted it actually makes the whole thing a non-starter
You want a protocol that gives consistent "global" state without any centralized / trusted users - blockchain/bitcoin is one of the only technical solutions to provide that.
I agree that it's a garbage solution in practice, but that's why it's got cryptoshit bundled in.
A potential different solution to DNS monopoly, if that is a problem that needs solving, is multiple name-resolution providers that have differing records on what name points where. (The tradeoff is that an owner may need to register their name with multiple different providers).
The world you describe, effectively with multiple roots, is coming. Russia have a switch (they’ve even tested it), to anycast out the root DNS IPs within the country, and block them externally. In theory this doesn’t make another “internet” (if IP space is still globally routable,) but in practice it does. Don’t be surprised if other countries follow suit (should they fail to leverage control of current infra via ITU or something.)
I did this with a website I liked which had let the domain expire. It worked for quite some time, until the VPS/whatever expired too. Good thing the Internet Archive is a thing.
Obviously you are technically correct.
What’s the single point of failure?