chiark / gitweb /
distorted.lisp: Include the correct TLSA record details for SMTP.
[zones] / Makefile
CommitLineData
5c420db9
MW
1### -*-makefile-*-
2###
3### Makefile for the DNS zones I maintain.
4###
5### (c) 2011 Mark Wooding
6
7###--------------------------------------------------------------------------
8### Silent-rules machinery.
9
10V = 0
11v_tag = $(call v_tag_$V,$1)
12v_tag_0 = @printf " %-6s %s\n" "$1" "$@";
13
14V_AT = $(V_AT_$V)
15V_AT_0 = @
16
17###--------------------------------------------------------------------------
18### Programs and options.
19
d7af5ae7 20## Zone checking.
5c420db9
MW
21CHECKZONE = named-checkzone -i full \
22 -k fail -M fail -n fail -S fail -W fail
23
d7af5ae7
MW
24## Zone installation.
25MASTER = localhost
38c2de7c
MW
26inside_MASTER = precision
27
d7af5ae7
MW
28ifeq ($(MASTER),localhost)
29ZONEINST = userv zoneconf install
30else
31ZONEINST = ssh zoneconf@$(MASTER)
32endif
33
5c420db9
MW
34###--------------------------------------------------------------------------
35### Utility functions.
36
37dir-nosl = $(patsubst %/,%,$(dir $1))
38
39###--------------------------------------------------------------------------
40### Keeping all of the files straight.
41
42## Establish a default target. We'll sort out what it does later.
43all:
44.PHONY: all
45
46## Things to clean.
47CLEANFILES =
48CLEANDIRS =
49REALCLEANFILES = $(CLEANFILES)
50REALCLEANDIRS = $(CLEANDIRS)
51
52## We work in terms of `zonesets'. Each one corresponds to a Lisp source
53## file to be passed to `zone'. A zoneset has a number of different nets
54## associated with it, in the variable zoneset_NETS, and we must run it
55## through `zone' once for each net. The zoneset will make a number of
56## zones, listed in zoneset_ZONES.
57ZONESETS =
58
59###--------------------------------------------------------------------------
60### The distorted.org.uk zones.
61
62ZONESETS += distorted
63
4a487d58 64distorted_VIEWS = inside outside
38c2de7c 65distorted_outside_NETS = dmz jump
9e4bef79 66distorted_inside_NETS = any unsafe colo vpn upn
5c420db9 67
b420e5ee 68distorted_all_ZONES += distorted.org.uk
652c34be 69
f5c3343e
MW
70distorted_all_ZONES += 195.113.2.81.in-addr.arpa
71distorted_all_ZONES += 128-143.238.187.81.in-addr.arpa
b29264c5
MW
72distorted_all_ZONES += 64-79.198.13.212.in-addr.arpa
73
74180153 74distorted_all_ZONES += 199.29.172.in-addr.arpa
5c420db9 75
652c34be 76distorted_all_ZONES += 9.d.1.0.0.0.0.0.8.a.b.0.1.0.0.2.ip6.arpa
f5c3343e 77distorted_all_ZONES += 2.9.c.0.0.b.8.0.1.0.0.2.ip6.arpa
652c34be
MW
78distorted_all_ZONES += 9.d.1.0.8.a.b.0.1.0.0.2.ip6.arpa
79
f54dd5ce
MW
80distorted_outside_NSDIFF = -sradius.dmz.distorted.org.uk
81
5c420db9 82###--------------------------------------------------------------------------
61097cd6 83### Other zones.
5c420db9 84
8dcb3700
MW
85## binswood.org.uk
86ZONESETS += binswood
87binswood_VIEWS = outside
88binswood_all_ZONES += binswood.org.uk
89binswood_all_ZONES += 27.165.10.in-addr.arpa
90
3a772cfb
MW
91## escorted.org.uk
92ZONESETS += escorted
93escorted_VIEWS = outside
94escorted_all_ZONES += escorted.org.uk
95
0885bc47
MW
96## odin.gg
97ZONESETS += odin
98odin_VIEWS = outside
99odin_all_ZONES = odin.gg
100
39c01832 101###--------------------------------------------------------------------------
5c420db9
MW
102### Zone construction machinery.
103
104ZONE = zone
105V_ZONE = $(call v_tag,ZONE)$(ZONE)
106
107.SECONDEXPANSION: #sorry
108
109## For each net/zoneset pair, we make a stamp file net/zoneset.stamp to
110## remember that we've made the corresponding zones.
111ALL_ZONESTAMPS = $(foreach s,$(ZONESETS), \
112 $(patsubst %,%/$s.zonestamp,$($s_VIEWS)))
113$(ALL_ZONESTAMPS) : %.zonestamp : $$(notdir $$*).lisp hosts.lisp
114 $(V_AT)mkdir -p $(dir $*)
115 $(V_ZONE) -d$(dir $*) -fview/$(call dir-nosl,$*)$(hack \
d7af5ae7
MW
116 hack) $(addprefix -s, \
117 $($(notdir $*)_$(call dir-nosl,$*)_NETS)) $<
5c420db9
MW
118 $(V_AT)touch $@
119all: $(ALL_ZONESTAMPS)
120CLEANFILES += $(sort $(foreach s,$(ZONESETS), \
121 $(foreach v,$($s_VIEWS), \
122 $v/*.zonestamp $v/*.zone)))
123REALCLEANFILES += $(sort $(foreach s,$(ZONESETS), \
124 $(foreach v,$($s_VIEWS), \
125 $v/*.serial)))
126REALCLEANDIRS += $(sort $(foreach s,$(ZONESETS),$($s_VIEWS)))
127
128## Now explain that each generated zone file depends on the corresponding
129## zonestamp. This is where things start getting a little hairy.
130$(foreach s,$(ZONESETS), \
131 $(foreach v,$($s_VIEWS), \
132 $(foreach z,$($s_all_ZONES) $($s_$v_ZONES), \
133 $(eval $v/$z.zone: $v/$s.zonestamp))))
134
f54dd5ce
MW
135## Prepare a mapping from zone names back to their owning zonesets.
136$(foreach s,$(ZONESETS), \
137 $(foreach z,$(sort $(foreach v,$($s_VIEWS), \
138 $($s_all_ZONES) $($s_$v_ZONES))), \
139 $(eval $z_ZONESET = $s)))
140
5c420db9
MW
141## Now we have to check the individual zone files.
142ALL_ZONECHECKS = $(foreach s,$(ZONESETS), \
143 $(foreach v,$($s_VIEWS), \
144 $(foreach z,$($s_all_ZONES) $($s_$v_ZONES), \
145 $v/$z.check)))
146$(ALL_ZONECHECKS) : %.check : %.zone
147 $(call v_tag,CHECK)\
148 { $(CHECKZONE) $(notdir $*) $^ || kill $$$$; } | \
149 { grep -Ev 'loaded serial|OK' || :; }
150check: $(ALL_ZONECHECKS)
151.PHONY: check $(ALL_ZONECHECKS)
152
f54dd5ce
MW
153## If nsdiff(1) is available then we can show what changes we will make if
154## we install the new zone files.
155ALL_ZONEDIFFS = $(foreach s,$(ZONESETS), \
156 $(foreach v,$($s_VIEWS), \
157 $(foreach z,$($s_all_ZONES) $($s_$v_ZONES), \
158 $v/$z.zonediff)))
3f954bac 159run-nsdiff = nsdiff -v "" $2 \
f54dd5ce
MW
160 $($($(call notdir,$1)_ZONESET)_$(call dir-nosl,$1)_NSDIFF) \
161 $(call notdir,$1) $1.zone
162$(ALL_ZONEDIFFS) : %.zonediff : %.zone
163 $(call v_tag,NSDIFF)$(call run-nsdiff,$*,-q); \
164 rc=$$?; case $$rc in 1) $(call run-nsdiff,$*); rc=$$? ;; esac; \
23ca64ab 165 case $$rc in 0 | 1) : ;; *) exit $$rc ;; esac
f54dd5ce
MW
166diff: $(ALL_ZONEDIFFS)
167
d7af5ae7
MW
168## Finally we have to install the zone files.
169ALL_INSTALLS = $(foreach s,$(ZONESETS), \
170 $(foreach v,$($s_VIEWS), \
171 $(foreach z,$($s_all_ZONES) $($s_$v_ZONES), \
172 $v/$z.inst)))
173$(ALL_INSTALLS) : %.inst : %.check
174 $(call v_tag,INST)$(ZONEINST) \
175 $(call dir-nosl,$*) $(notdir $*) <$*.zone
176install: $(ALL_INSTALLS)
177.PHONY: install $(ALL_INSTALLS)
178
5c420db9
MW
179## Files to clean.
180clean:
181 rm -f $(CLEANFILES)
182 [ "$(CLEANDIRS)x" = x ] || rmdir $(CLEANDIRS) || :
183realclean:
184 rm -f $(REALCLEANFILES)
185 [ "$(REALCLEANDIRS)x" = x ] || rmdir $(REALCLEANDIRS) || :
186.PHONY: clean realclean
187
188###----- That's all, folks --------------------------------------------------