This means that I can always use public DNS servers like 1.1.1.1, 8.8.8.8, nextDNS etc
This is not "done right" by any stretch but it's extremely low effort to set up and has never once failed me, unlike countless complex meshy things.
This means that I can always use public DNS servers like 1.1.1.1, 8.8.8.8, nextDNS etc
This is not "done right" by any stretch but it's extremely low effort to set up and has never once failed me, unlike countless complex meshy things.
I use the form of hostname.int.example.com for everything inside my home network. None of which is accessible to the outside world. I use LetsEncrypt with DNS validation to get the certificates.
If it does then you don't have to mess with your public DNS whenever you want to add or renew certificates for home machines.
I'm using the free DNS my registrar provides, which doesn't provide API access unless you upgrade to their paid DNS service and so if I could use a local DNS server for the ACME challenges for the home network I could pick one that is friendly to automation.
I use Cloudflare for DNS and it is free to use the API.
Note that int is a valid TLD:
Lots of folks were using "dev" as a sub-domain which was fine until ICANN decide to give Google a TLD:
* https://en.wikipedia.org/wiki/.dev
So if you generally had "search example.com" in you resolv.conf, and were in the habit of having "web01.dev" in places, behaviour may have changed if you were suddenly on a machine that had the "search" line missing (or something else).
That won't prevent me from getting a ticket saying "the network is down".
I always use FQDNs for everything.
Removing attack surface is better than trying to hide it.
The juice isn't really worth the squeeze for the token spend any more than it was worth the human energy.
I'd prefer this over split DNS, any day.
I did set up tailscale, way back. After using it a few times to test, it failed me when I really needed it (I was out of the country and it failed - can't remember exactly what went wrong but it wwas 100% 'in my tailscale account'). I immediately dropped it and went back to OpenVPN (shit but reliable) before building my current setup.