validate zone on the nameservers

This block is part of the dns group and was last modified in core v15.0.0.

validate zone on the nameservers v15.0.0

Run named-checkzone on every nameserver. Writes nothing anywhere, on any node.

In pins 3 + flow
  • flow
    flow
  • Zone required
    value

    The zone name, for example deverence.nl.

  • Zone file required
    value

    The rendered zone file, exactly as it would be pushed.

  • Nameservers required
    array

    Each {name, host, port, user, key_path, known_hosts_path}. Paths only : never key material.

Out pins 8 + flow
  • flow
    flow
  • Success
    condition

    True when every node could be asked. Whether they passed is on the passed pin.

  • Zone
    value

    The zone that was validated.

  • Passed everywhere
    condition

    True only when named-checkzone passed on every node. This is the gate the push needs.

  • Results
    array

    Per node: name, host, ok, output, exit_code, checksum, zone.

  • Checksum
    value

    sha256 of the exact bytes checked. The push matches on this.

  • Passed count
    number

    How many nodes accepted the file.

  • Node count
    number

    How many nodes were asked.

  • Error
    value

    Why the check could not run at all.

Runs named-checkzone for this zone file on EVERY nameserver in the nodes list and reports per node. It never writes: the file is handed to the parser on stdin and discarded. This is a separate fan-out ahead of any write, not a per-node try-and-see, because a DNS server serving a syntactically valid but truncated zone is worse than one serving yesterday's : so 'does this parse everywhere' is answered in full before 'shall we replace anything' is asked. passed comes back true only when every node passed. results carries {name, host, ok, output, exit_code, checksum, zone} per node, and checksum is a sha256 of the exact bytes checked: dnszone_push demands a passing result with a MATCHING checksum for every node it is about to write to, so a flow cannot render, check, edit and then push a different file. Each node is {name, host, port, user, key_path, known_hosts_path}. Key MATERIAL must never appear on the pin : only paths : and the block refuses a node object carrying private_key, key, password, passphrase or secret. Refuses a file still carrying the @SERIAL@ placeholder, since those would not be the bytes pushed.

named-checkzone
validate zone
check zone

A typical wiring for validate zone on the nameservers: a function trigger starts the flow; value feeds the zone pin; value feeds the zone_file pin; with values feeds the nodes pin; the flow out pin feeds debug.

Studio canvas example for the validate zone on the nameservers block: typical wiring for validate zone on the nameservers.

Used in these guides

These documentation pages use or explain this block:

Version history

Introduced in v15.0.0.


Back to dns Return to the main group to view all sub-groups Back to DNS zones Return to the group to view all blocks within this group