Domain ownership

Domains are shared infrastructure. They do not belong to one page, one Worker, or one Hugo repository.

DNS configuration is owned in /Volumes/Tarmac/code/dnsControl, using DNSControl with Cloudflare. Site repositories document the hostnames they need and the assumptions they make, but they do not duplicate full zone state.

Rule#

Manage DNS in DNSControl. Document hostname intent in the site that depends on it.

Source of truth#

  • DNS records: /Volumes/Tarmac/code/dnsControl
  • DNS provider and runtime control plane: Cloudflare
  • Site routing assumptions: the site or Worker repository that depends on the route
  • Decision boundary: repository ADRs, then the relevant governance page

Site documentation should include#

  • canonical hostnames
  • brand hostnames
  • Worker hostnames and routing assumptions
  • verification records the site requires
  • expected Cloudflare Access or protection boundaries
  • links to the DNSControl change when DNS is affected

Site documentation should not include#

  • a full DNS zone inventory
  • plaintext credentials
  • dashboard-only instructions that pretend to be the source of truth
  • copied DNSControl ADR content

Exceptions#

Cloudflare-owned or provider-owned records may be reported without being managed directly. Emergency dashboard changes should be reconciled into DNSControl when the record is meant to remain managed.