From f21561bab9e8f2b8f811609a54d29c6b17cc5bca Mon Sep 17 00:00:00 2001 From: Spendlik Date: Tue, 11 Aug 2026 08:40:18 +0000 Subject: [PATCH] =?UTF-8?q?Update=20DNS/DDNS=20phases=20to=20reflect=20CNA?= =?UTF-8?q?ME-based=20DNS=20architecture=20(2026-08-10=20change)=20?= =?UTF-8?q?=E2=80=94=20removes=20obsolete=20per-subdomain=20A=20record=20+?= =?UTF-8?q?=20DDNS=20script=20step?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- 114_koillection_deployment.md | 21 ++++++++++----------- 1 file changed, 10 insertions(+), 11 deletions(-) diff --git a/114_koillection_deployment.md b/114_koillection_deployment.md index 5e7293b..22f5692 100644 --- a/114_koillection_deployment.md +++ b/114_koillection_deployment.md @@ -3,7 +3,7 @@ > Status: **PLANNED** — not yet deployed > CT ID: 114 · IP: 192.168.1.114 > Domain: `collections.spendlik.sk` -> Last updated: 2026-07-03 +> Last updated: 2026-08-11 --- @@ -290,22 +290,20 @@ docker compose restart koillection ## Phase 8 — DNS Record +> ℹ️ **Updated 2026-08-10**: All `*.spendlik.sk` subdomains are now **CNAME** records pointing at the root `spendlik.sk`. Only the root `spendlik.sk` A record holds an IP — WebSupport rejects any duplicate IP value elsewhere in the zone. Do **not** create an A record for this subdomain. + In WebSupport admin panel: -1. Add A record: `collections` → current public IP -2. **Check both DNS management pages** +1. Add **CNAME** record: `collections` → `spendlik.sk` +2. Check both DNS management pages 3. Note the numeric record ID 4. Add to `00_index.md` DNS table ---- - -## Phase 9 — DDNS Updater (CT 108) - -Enter CT 108, add `collections.spendlik.sk` to `/usr/local/bin/ddns-update.sh` using the record ID from Phase 8, following the existing script pattern. +> ✅ No DDNS updater step is needed for this subdomain. `ddns-update.sh` on CT 108 only updates the root A record on IP change; this CNAME resolves through automatically. (Previously this guide had a separate "add to DDNS script" phase — that step is obsolete under the current DNS architecture and has been removed.) --- -## Phase 10 — Authelia Protection (CT 102) +## Phase 9 — Authelia Protection (CT 102) Enter CT 102, edit `/etc/authelia/configuration.yml`. Add to `access_control.rules`: @@ -326,7 +324,7 @@ Add the Authelia middleware to the nginx vhost in CT 101 (follow the pattern fro --- -## Phase 11 — First Login & Initial Setup +## Phase 10 — First Login & Initial Setup Open `https://collections.spendlik.sk` from mobile data (hairpin NAT — never test from LAN). @@ -338,7 +336,7 @@ On first load, Koillection will prompt you to create an admin account. Do so, th --- -## Phase 12 — Collection Setup +## Phase 11 — Collection Setup Recommended collection structure. Create each as a top-level Collection: @@ -431,3 +429,4 @@ mkdir -p /opt/koillection/backups | certbot corrupts nginx config | Always inspect after issuance | | Large photo uploads rejected | Increase `client_max_body_size` in nginx vhost | | HTTPS redirect loop | Set `HTTPS_ENABLED=1` in `.env` and restart the koillection container after SSL is in place | +| DNS record type | Use CNAME → `spendlik.sk`, never a per-subdomain A record (see Phase 8) |