Secondary mirror should accept requests for www.tails.net
Right now:
-
www.tails.net
is aCNAME
record fortails.net
-
tails.net
is anA
record and randomly returns the IPs ofwww1
andwww2
-
www2
doesn't have the TLS cert and Nginx config forwww.tails.net
.
Problems:
- Our current monitoring for
www.tails.net
sometimes hitswww2
and flags a failure. - We don't have consistent TLS checks for all domains in all mirrors.
To-do
-
Add a www.tails.net
→tails.net
redirect towww2
→ puppet-tails!159 (merged) -
Pin TLS checks of tails.net
andwww.tails.net
to specific IPs → puppet-tails!160 (merged)
Edited by Zen Fu