MASTER = localhost
inside_MASTER = precision
-
ifeq ($(MASTER),localhost)
ZONEINST = userv zoneconf install
else
ZONESETS += distorted
distorted_VIEWS = inside outside
-distorted_outside_NETS = dmz jump
-distorted_inside_NETS = unsafe colo
+distorted_outside_NETS = dmz
+distorted_inside_NETS = any unsafe vpn upn
-distorted_all_ZONES += distorted.org.uk io.distorted.org.uk
-distorted_all_ZONES += 199.29.172.in-addr.arpa
+distorted_all_ZONES += distorted.org.uk
-###--------------------------------------------------------------------------
-### The harlequin.org.uk zones.
+distorted_all_ZONES += 195.113.2.81.in-addr.arpa
+distorted_all_ZONES += 128-143.238.187.81.in-addr.arpa
+distorted_all_ZONES += 64-79.12.169.217.in-addr.arpa
+distorted_all_ZONES += 2.9.c.0.0.b.8.0.1.0.0.2.ip6.arpa
+distorted_all_ZONES += 9.d.1.0.8.a.b.0.1.0.0.2.ip6.arpa
-ZONESETS += harlequin
-
-harlequin_VIEWS = inside outside
-harlequin_outside_NETS = dmz
-harlequin_inside_NETS = unsafe
+distorted_all_ZONES += 199.29.172.in-addr.arpa
-harlequin_all_ZONES = harlequin.org.uk
+distorted_outside_NSDIFF = -sradius.dmz.distorted.org.uk
###--------------------------------------------------------------------------
-### The felixpearce.com zones.
+### Other zones.
-ZONESETS += felixpearce
+## binswood.org.uk
+ZONESETS += binswood
+binswood_VIEWS = outside
+binswood_all_ZONES += binswood.org.uk
+binswood_all_ZONES += 27.165.10.in-addr.arpa
-felixpearce_VIEWS = inside outside
-felixpearce_outside_NETS = dmz
-felixpearce_inside_NETS = unsafe
+## escorted.org.uk
+ZONESETS += escorted
+escorted_VIEWS = outside
+escorted_all_ZONES += escorted.org.uk
-felixpearce_all_ZONES = felixpearce.com
+## odin.gg
+ZONESETS += odin
+odin_VIEWS = outside
+odin_all_ZONES = odin.gg
###--------------------------------------------------------------------------
### Zone construction machinery.
ZONE = zone
V_ZONE = $(call v_tag,ZONE)$(ZONE)
+ZONEOPTS =
.SECONDEXPANSION: #sorry
$(V_AT)mkdir -p $(dir $*)
$(V_ZONE) -d$(dir $*) -fview/$(call dir-nosl,$*)$(hack \
hack) $(addprefix -s, \
- $($(notdir $*)_$(call dir-nosl,$*)_NETS)) $<
+ $($(notdir $*)_$(call dir-nosl,$*)_NETS)) $(ZONEOPTS) $<
$(V_AT)touch $@
all: $(ALL_ZONESTAMPS)
CLEANFILES += $(sort $(foreach s,$(ZONESETS), \
$(foreach z,$($s_all_ZONES) $($s_$v_ZONES), \
$(eval $v/$z.zone: $v/$s.zonestamp))))
+## Prepare a mapping from zone names back to their owning zonesets.
+$(foreach s,$(ZONESETS), \
+ $(foreach z,$(sort $(foreach v,$($s_VIEWS), \
+ $($s_all_ZONES) $($s_$v_ZONES))), \
+ $(eval $z_ZONESET = $s)))
+
## Now we have to check the individual zone files.
ALL_ZONECHECKS = $(foreach s,$(ZONESETS), \
$(foreach v,$($s_VIEWS), \
check: $(ALL_ZONECHECKS)
.PHONY: check $(ALL_ZONECHECKS)
+## If nsdiff(1) is available then we can show what changes we will make if
+## we install the new zone files.
+ALL_ZONEDIFFS = $(foreach s,$(ZONESETS), \
+ $(foreach v,$($s_VIEWS), \
+ $(foreach z,$($s_all_ZONES) $($s_$v_ZONES), \
+ $v/$z.zonediff)))
+run-nsdiff = nsdiff -v "" $2 \
+ $($($(call notdir,$1)_ZONESET)_$(call dir-nosl,$1)_NSDIFF) \
+ $(call notdir,$1) $1.zone
+$(ALL_ZONEDIFFS) : %.zonediff : %.zone
+ $(call v_tag,NSDIFF)$(call run-nsdiff,$*,-q); \
+ rc=$$?; case $$rc in 1) $(call run-nsdiff,$*); rc=$$? ;; esac; \
+ case $$rc in 0 | 1) : ;; *) exit $$rc ;; esac
+diff: $(ALL_ZONEDIFFS)
+
## Finally we have to install the zone files.
ALL_INSTALLS = $(foreach s,$(ZONESETS), \
$(foreach v,$($s_VIEWS), \