gibdns-gcore
gibdns provider for Gcore DNS. Hosts such as gibcert execute this binary to publish ACME DNS-01 TXT records.
Gcore's API has no TLSA support. Do not use this provider for automatic DANE publication.
| Protocol | TXT | TLSA | Zone discovery |
|---|---|---|---|
gibdns/draft-01 |
yes | no | yes |
Install
Download the archive or .deb for your OS from the
releases page.
Debian package (installs to /usr/libexec/gibdns):
sudo dpkg -i gibdns-gcore_*_linux_amd64.deb
Tarball:
sudo install -D -m 0755 gibdns-gcore /usr/local/libexec/gibdns/gibdns-gcore
From source:
make install PREFIX=/usr/local
The binary is not an interactive CLI and is intentionally not installed on
PATH. Confirm the installation, then let the host invoke it:
# Debian package:
test -x /usr/libexec/gibdns/gibdns-gcore
# Source or tarball install:
test -x /usr/local/libexec/gibdns/gibdns-gcore
Use /usr/libexec/gibdns/gibdns-gcore for a Debian package or
/usr/local/libexec/gibdns/gibdns-gcore for a source or tarball install in
host configuration. See Using gibdns
for the host and provider split.
Use with gibcert
Store a Gcore permanent API key at /etc/gibcert/gcore-api-key with mode
0600. Then:
provider gcore {
type dns
driver exec
command /usr/libexec/gibdns/gibdns-gcore
zone example.com.
secret api_key {
file /etc/gibcert/gcore-api-key
}
}
certificate wildcard-example.com {
account letsencrypt
names example.com *.example.com
challenge dns-01 {
provider gcore
propagation-timeout 120s
}
}
zone is optional because this provider advertises zone discovery. Set it
when you want an exact zone selector. If installed from source or a tarball,
use /usr/local/libexec/gibdns/gibdns-gcore instead.
gibcert binding details are in External DNS Providers.
Secrets
api_key(required): a Gcore permanent API key
Config
api_url(optional)
Minimum TTL depends on the Gcore plan. The provider advertises 120 seconds as
a conservative hint. Patch is a full RRset replace, so concurrent_safe_patch
is false; use if_revision. TLSA is not advertised.
This provider talks to the official Gcore DNS SDK rather than libdns/gcore.
Development
make test
make build
make snapshot
Publish a tagged release with make release. That target runs GoReleaser via
go run; a GITEA_TOKEN with package/release access is required.