deSEC provider
The deSEC provider implements all Protocol53 operations with deSEC’s v1 API.
Installation
Until the first release, use the provider’s Git coordinate:
{:deps {com.outskirtslabs/protocol53-desec
{:git/url "https://github.com/outskirtslabs/protocol53.git"
:git/sha "4a0ad834256d7e1e1a6a95936ea5e7ca14f13988"
:deps/root "providers/desec" }}}
The provider module also brings in the shared Protocol53 API.
Authentication
Create a basic token through deSEC’s token management interface.
(require ' [ol.protocol53.desec :as desec])
(def dns
(desec/provider {:token "token" }))
Pass a caller-built java.net.http.HttpClient as :http-client when advanced
HTTP policy requires Java interop.
TTL Policy
A deSEC RRset cannot have a TTL below 3600 seconds. The provider always clamps lower requested values to 3600 and returns the value deSEC stored. TTL belongs to the complete RRset, so all records with the same owner and type share one TTL. When setting an RRset whose input records disagree, the first record’s TTL is used.
RRset and Rate-Limit Behavior
Append and delete operations read the zone before applying one atomic bulk
write. As with other Protocol53 providers, callers must coordinate concurrent
mutations of the same RRset. HTTP 429 responses are retried according to
deSEC’s Retry-After header while the operation deadline permits.
Integration Tests
|
Run the lifecycle suite only against a dedicated disposable zone. It creates,
replaces, and deletes DNS records whose effective owner starts with
|
Set these variables in the process environment or the repository .env file.
Process values take precedence over .env values.
| Variable | Required | Description |
|---|---|---|
|
yes |
Basic deSEC token with access to the test domain. |
|
yes |
Dedicated zone name, with or without a trailing dot. |
Run every configured provider integration suite from the repository root:
bb test:integration
The deSEC wrapper ignores TTL differences in the shared lifecycle comparison because all fixture TTLs below 3600 are clamped. Provider-specific tests still assert the exact 3600-second policy. Do not run concurrent lifecycle suites against one zone.