1 # the primary (hidden master) nameserver does bind zone file stuff and letsencrypt cert handling
2 class roles::dns_primary {
5 ssh::authorized_key_collect { 'dns_primary-dnsadm':
6 target_user => 'dnsadm',
7 collect_tag => 'dns_primary',
9 ssh::authorized_key_collect { 'dns_primary-letsencrypt':
10 target_user => 'letsencrypt',
11 collect_tag => 'dns_primary',
13 ssh::keygen {'dnsadm': }