igneum/infra/seed-nodes/dns.sh
igneum-labs 72351e8270 Testnet seeds: NET=testnet profile for the seed scripts, seeds-testnet.tsv (3 Hetzner VMs), dns.sh (deSEC), the public RPC allowlist and nginx site, build-job.mjs forwards --node-tests
seed1.testnet nbg1 195.201.35.33, seed2.testnet ash 5.161.232.205, seed3.testnet sin 5.223.52.210 (5 October 2026). Ports 26810/26811/28810/26890
from seed.env; provision-seed.sh BUILD_WHERE=cross takes the PC build job's Linux igneumd from infra/cross/out.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:46:22 +00:00

37 lines
2.3 KiB
Bash
Executable file

#!/usr/bin/env bash
# DNS for the seeds (5 October 2026): one A record per seed in seeds-testnet.tsv (seedN.testnet.igneum.network) and
# rpc.testnet.igneum.network at the first seed (the public JSON-RPC behind nginx, node/install-rpc.sh), through the
# deSEC API (igneum.network's nameservers are ns1.desec.io and ns2.desec.org; token at ~/.config/igneum/desec-token,
# never printed). Idempotent: an existing record set is replaced. NET=testnet ./dns.sh [--check]
. "$(dirname "$0")/lib.sh"
[ "$NET" = testnet ] || die "dns.sh is for NET=testnet (the devnet seed has no DNS name)"
DESEC_TOKEN_FILE="${DESEC_TOKEN_FILE:-$HOME/.config/igneum/desec-token}"
[ -s "$DESEC_TOKEN_FILE" ] || die "no token at $DESEC_TOKEN_FILE"
ZONE="igneum.network"
auth=(-H "Authorization: Token $(tr -d '[:space:]' < "$DESEC_TOKEN_FILE")" -H "Content-Type: application/json")
put() { # put <subname> <ip>; deSEC answers 429 to more than about one write a second, so each call retries after a pause
local sub="$1" ip="$2" code try
for try in 1 2 3 4 5 6; do
code=$(curl -s -o /dev/null -w '%{http_code}' --max-time 30 "${auth[@]}" -X PUT "https://desec.io/api/v1/domains/$ZONE/rrsets/$sub/A/" \
-d "{\"subname\":\"$sub\",\"type\":\"A\",\"ttl\":3600,\"records\":[\"$ip\"]}")
if [ "$code" = 404 ]; then
code=$(curl -s -o /dev/null -w '%{http_code}' --max-time 30 "${auth[@]}" -X POST "https://desec.io/api/v1/domains/$ZONE/rrsets/" \
-d "{\"subname\":\"$sub\",\"type\":\"A\",\"ttl\":3600,\"records\":[\"$ip\"]}")
fi
case "$code" in 200|201) log "$sub.$ZONE A $ip ($code)"; sleep 2; return 0 ;; 429) sleep $((try * 3)) ;; *) die "$sub.$ZONE: http $code" ;; esac
done
die "$sub.$ZONE: rate limited six times"
}
if [ "${1:-}" = --check ]; then
while IFS=$'\t' read -r name _ _ ip _; do [ -n "$name" ] || continue; printf '%s.%s -> %s (want %s)\n' "$name" "$ZONE" "$(dig +short "$name.$ZONE" @ns1.desec.io | tr '\n' ' ')" "$ip"; done < "$SEEDS_TSV"
printf 'rpc.%s.%s -> %s\n' "$DNS_ZONE_SUB" "$ZONE" "$(dig +short "rpc.$DNS_ZONE_SUB.$ZONE" @ns1.desec.io | tr '\n' ' ')"
exit 0
fi
first=""
while IFS=$'\t' read -r name _ _ ip _; do
[ -n "$name" ] || continue
put "$name" "$ip"
[ -n "$first" ] || first="$ip"
done < "$SEEDS_TSV"
[ -n "$first" ] && put "rpc.$DNS_ZONE_SUB" "$first"
log "done; propagation: dig +short seed1.$DNS_ZONE_SUB.$ZONE"