Open mweinelt opened 2 years ago
I'm not sure if that's possible. debian.map.fastlydns.net.
looks like something custom they got from Fastly.
https://support.fastly.com/hc/en-us/articles/360035069912-IPv6-support doesn't mention fastlydns.
I agree that it's weird that ns1.fastly.net
doesn't reply AAAA. Luckily, most of the time I would expect an intermediate DNS to reply to the query but still.
The problem is that ns1.fastly.net
is not reachable via IPv6, not that it does not reply with a AAAA record (which it does for me).
❯ echo ns{1,2,3,4}.fastly.net | xargs -n 1 host -t AAAA
ns1.fastly.net has no AAAA record
ns2.fastly.net has no AAAA record
ns3.fastly.net has no AAAA record
ns4.fastly.net has no AAAA record
I don't know... so poke their support? https://support.fastly.com
It might work even without any customer account. Any better ideas? EDIT: I did look into their docs further and found nothing.
Query sent.
I'll need our account ID, apparently.
We may be able to squeeze you into our IPv6 authoritative DNS delivery beta program, If you're happy to do so. You will need to agree to our Terms of Service conditions which should be with you soon.
Can you confirm your account ID please.
EDIT: I hope "beta" doesn't mean anything risky really.
EDIT2: we're following up the support thread now.
Nothing risky is involved but we would like to make you aware of the fact that performance is not as tuned as for our IPv4 only DNS answers so you may see something there. You will also need to work with us to provide us with insight into any performance issues you may see. We will use that insight to help improve the performance. If you're are ok with this we are happy to include you.
Sounds OK to me, but I expect that also some else should ACK it before proceeding.
I don't expect that speed of DNS itself could be as significant for us in this case, as there are few names and will be mostly used in large batches (amortization through caching).
Hmm, their "beta" wording isn't as encouraging as I hoped, e.g.
Fastly strongly advises against using production traffic for Beta products due to their dynamic nature.
Yeah, let's wait.
Happy 1 year anniversary of this issue. Just contacted Fastly support about this to see what they say.
Update: they said I'd hear back tomorrow.
IPv6 has been enabled on all our distributions. However, it involves a configuration change in our DNS. I'm confirming with Fastly that we should in fact replace the CNAMEs with A's and AAAA's on our end.
are there any news on this topic?
Recursively resolving
cache.nixos.org
in an IPv6-only setup is impossible, since thefastly.com
authoritative nameservers don't provide IPv6 connectivity.Debian, they also host their cache at fastly, have their CNAME set to something below
fastlydns.net
, which does have full IPv6 connectivity.Can we find out what this is, and how we can get it, too?