Repository navigation
Restructure docs and harden deployment manifests (#294) - #304
Open
timothymiller wants to merge 5 commits into
Open
timothymiller wants to merge 5 commits into
timothymiller wants to merge 5 commits into
Conversation
- docker: docker-compose.yml is now env mode, legacy moved to docker-compose.legacy.yml; drop obsolete version key and PUID/PGID - systemd: absolute ExecStart, optional EnvironmentFile for env mode, run once per timer tick, sandboxing (DynamicUser, ProtectSystem=strict, RestrictAddressFamilies incl. AF_NETLINK for local.iface providers) - helm: appVersion 2.2.0, chart 0.2.0; notification/heartbeat URLs moved into the Secret, new deleteOnFailure / rejectCloudflareIps / WAF values, restricted securityContext, Recreate strategy - k8s: env-mode manifest (Namespace, Secret, Deployment) pinned to 2.2.0; legacy manifest kept as cloudflare-ddns.legacy.yml
- env-example: rejected placeholder token, token permissions, REJECT_CLOUDFLARE_IPS, single SHOUTRRR line, Uptime Kuma URL note - config-example.json: api_token only, recordComment - SECURITY.md: 2.2.x supported, unprefixed tag example, token scopes
Merge the 2.1.1, 2.1.2 and 2.2.0 release notes into a single changelog (newest first) and add an Unreleased section for the upcoming behavior and documentation changes.
- Quick start leads with exact token permissions; compose examples drop the version key and IPv4-only example no longer uses host networking - New how-it-works and failure-safety sections, configuration by topic, a single environment variable reference plus deprecated aliases - Fix IPv4 default provider (cloudflare.trace, #294), Pushover URL format, scheduling claims, broken helpful links, k8s namespace usage - Add deployment (Compose, Helm, manifest, systemd), security notes and troubleshooting sections - Move legacy config.json mode to docs/legacy-config.md with activation rules, env var applicability, purgeUnknownRecords semantics and a migration table
There was a problem hiding this comment.
🟡 Changes recommended
Deployment DNS, replica-safety, and documentation inaccuracies should be corrected before approval.
7 open findings
Validate the documented maximum TTL before API writes · New Enforce a single replica independently of the update strategy · New Enable host networking for the legacy IPv6 manifest · New Use ClusterFirstWithHostNet with host networking · New Document that in-flight updates continue after interruption · New Include none in configurations that can delete AAAA records · New Do not treat an empty provider value as IPv6 disablement · New
What changed in this PR
Restructures documentation and hardens Docker, Kubernetes, Helm, and systemd deployment configurations.
Changes:
- Consolidates and corrects documentation, release notes, and legacy configuration guidance.
- Adds hardened Kubernetes, Helm, Docker Compose, and systemd examples.
- Expands Helm configuration and secret handling.
| File | Description |
|---|---|
systemd/cloudflare-ddns.timer |
Adds randomized timer delay. |
systemd/cloudflare-ddns.service |
Adds environment mode and sandboxing. |
SECURITY.md |
Updates supported versions and security guidance. |
RELEASE_NOTES_2.2.0.md |
Removed after changelog consolidation. |
RELEASE_NOTES_2.1.2.md |
Removed after changelog consolidation. |
RELEASE_NOTES_2.1.1.md |
Removed after changelog consolidation. |
README.md |
Reorganizes configuration and deployment documentation. |
k8s/cloudflare-ddns.yml |
Rewrites the manifest for environment mode. |
k8s/cloudflare-ddns.legacy.yml |
Adds a legacy Kubernetes manifest. |
env-example |
Expands environment-variable guidance. |
docs/legacy-config.md |
Documents legacy mode and migration. |
docker/docker-compose.yml |
Makes environment mode the primary example. |
docker/docker-compose.legacy.yml |
Adds the legacy Compose deployment. |
docker/docker-compose-env.yml |
Removes the redundant environment-mode file. |
config-example.json |
Simplifies legacy authentication and adds comments. |
charts/cloudflare-ddns/values.yaml |
Adds configuration and security values. |
charts/cloudflare-ddns/templates/secret.yaml |
Moves credential-bearing URLs into Secrets. |
charts/cloudflare-ddns/templates/deployment.yaml |
Adds security, secret, and rollout settings. |
charts/cloudflare-ddns/templates/_helpers.tpl |
Adds Secret name and key helpers. |
charts/cloudflare-ddns/Chart.yaml |
Bumps chart and application versions. |
CHANGELOG.md |
Consolidates release history and unreleased changes. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| | `PROXIED` | `false` | Expression controlling which domains are proxied through Cloudflare | | ||
| | `RECORD_COMMENT` | (empty) | Comment attached to managed DNS records | | ||
| | `MANAGED_RECORDS_COMMENT_REGEX` | (empty) | Regex to identify which records are managed (empty = all) | | ||
| | `TTL` | `1` | Record TTL in seconds. `1` = automatic, and values below 30 also mean automatic. Cloudflare accepts up to 86400 | |
Comment on lines
7
to
+11
| spec: | ||
| replicas: {{ .Values.replicaCount }} | ||
| # Never run two instances at once (they would race on the same records). | ||
| strategy: | ||
| type: Recreate |
| labels: | ||
| app: cloudflare-ddns | ||
|
|
||
| spec: |
Comment on lines
+49
to
+51
| # Needed for IPv6 detection (IPv6 egress for cloudflare.trace and the | ||
| # local.iface providers). Remove it and set IP6_PROVIDER=none for IPv4 only. | ||
| hostNetwork: true |
| By default the first update runs at startup, then every 5 minutes. After the first run, each scheduled update is delayed by a random 0–20% of the interval so that many installations don't hit the Cloudflare API at the same moment. | ||
|
|
||
| ## 🔍 IP Detection Providers | ||
| On `SIGTERM` (`docker stop`, Kubernetes, systemd) or `SIGINT` (Ctrl+C) the process stops right away, deletes its records if `DELETE_ON_STOP=true`, and sends a final heartbeat. |
Comment on lines
+50
to
+52
| # Delete managed records when a deterministic provider (literal:, local, | ||
| # local.iface:, local.iface.stable:) reports no address for that family. | ||
| # Transient detection errors never delete records. |
| # local.iface.stable:<name>, url:<custom-url>, literal:<ip1>,<ip2>, none | ||
| # Options: cloudflare.trace, cloudflare.trace:<url>, cloudflare.doh, ipify, local, | ||
| # local.iface:<name>, local.iface.stable:<name>, url:<custom-url>, | ||
| # literal:<ip1>,<ip2> (comma or space separated), none (or empty) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Docs and deployment overhaul. Documents the behavior in #303 as current, so merge #303 first. Fixes #294.
Overlaps #300 (Pushover URI) and #293 (compose
version:): both fixes are included here. Merging those first will cause small README conflicts; resolve in favor of this branch.Docs
config.jsonmode moved todocs/legacy-config.md, with a legacy → env-var migration table.cloudflare.trace(Default IPv4 provider iscloudflare.trace#294); Pushover URI order; scheduling is@every/@once(not cron); env mode is triggered by any of seven variables, not just the token; Gotify/Telegram/generic webhook details; k8s namespace mismatch; broken "helpful links".RELEASE_NOTES_*.mdconsolidated intoCHANGELOG.mdwith an Unreleased section.SECURITY.md: supported 2.2.x, tags withoutvprefix, token permissions.Deployment
docker/docker-compose.ymlis now env mode; legacy moved todocker-compose.legacy.yml. Removedversion:and PUID/PGID; pinned tag.ExecStart, env mode viaEnvironmentFile, sandboxing (DynamicUser,ProtectSystem=strict, …).existingSecretsupport, new values (deleteOnFailure,rejectCloudflareIps, WAF options), pod/containersecurityContext,strategy: Recreate, secret checksum annotation, fixedexistingSecretKeybug.k8s/cloudflare-ddns.ymlrewritten for env mode; legacy manifest kept ask8s/cloudflare-ddns.legacy.yml.Not verified
helm lint/helm template(helm not installed locally; CI will run it).LoadCredential=drop-in for legacy mode (needs systemd ≥ 247).2.2.0; bump them when releasing Reliability fixes: SIGTERM, failed-write reporting, fail-closed config (#302, #292) #303.