Adding DNS role

This commit is contained in:
Ian Roddis
2026-04-21 10:07:06 -04:00
parent 3a873051e7
commit 043d315b80
14 changed files with 464 additions and 1 deletions
+20
View File
@@ -136,3 +136,23 @@ smtp_from: "noreply@{{ base_domain }}"
smtp_user: "noreply@{{ base_domain }}"
smtp_password: "changeme_smtp"
smtp_tls: "starttls"
# DNS / BIND9 — authoritative nameserver
bind_version: "9.18-22.04_beta"
# dns_server_ip must be the public IPv4 address of this server.
# Register ns1.{{ base_domain }} as a glue record at your domain registrar
# pointing to this IP, then set your domain's nameservers to ns1.{{ base_domain }}.
dns_server_ip: "changeme_server_public_ip"
dns_ns_hostname: "ns1.{{ base_domain }}"
dns_ttl: 3600
# DKIM — retrieve the public key from the Stalwart admin UI at
# mail.{{ base_domain }} → Settings → DKIM keys after first deployment.
# Leave empty to skip the DKIM TXT record until the key is available.
stalwart_dkim_selector: "default"
stalwart_dkim_public_key: "" # e.g. "MIGfMA0GCSqGSIb3DQEB..."
# DMARC — email authentication policy
dmarc_policy: "quarantine" # none | quarantine | reject
dmarc_rua: "mailto:dmarc-reports@{{ base_domain }}"
dmarc_ruf: "mailto:dmarc-forensics@{{ base_domain }}"