Domain ownership
Domains are shared infrastructure. They do not belong to one page, one Worker, or one Hugo repository.
DNS configuration is owned in /Volumes/Tarmac/code/dnsControl, using DNSControl with Cloudflare. Site repositories document the hostnames they need and the assumptions they make, but they do not duplicate full zone state.
Rule#
Manage DNS in DNSControl. Document hostname intent in the site that depends on it.
Source of truth#
- DNS records:
/Volumes/Tarmac/code/dnsControl - DNS provider and runtime control plane: Cloudflare
- Site routing assumptions: the site or Worker repository that depends on the route
- Decision boundary: repository ADRs, then the relevant governance page
Site documentation should include#
- canonical hostnames
- brand hostnames
- Worker hostnames and routing assumptions
- verification records the site requires
- expected Cloudflare Access or protection boundaries
- links to the DNSControl change when DNS is affected
Site documentation should not include#
- a full DNS zone inventory
- plaintext credentials
- dashboard-only instructions that pretend to be the source of truth
- copied DNSControl ADR content
Exceptions#
Cloudflare-owned or provider-owned records may be reported without being managed directly. Emergency dashboard changes should be reconciled into DNSControl when the record is meant to remain managed.