Three of the four failures in the week to 2026-09-23 (09-19, 09-21, 09-23)
had one signature. The Cloudflare zone lookup returned an empty body at its
15s cap, a bare json.load crashed with tracebacks instead of a cause, and the
script carried empty IDs on to a PATCH against zones//dns_records/.
Cloudflare rejected it, so there was no DNS impact, but only by accident.
- Cloudflare calls go through cf(): 3 announced tries, and a call counts
only when the body says success:true.
- success:true is not trusted as shape. pick() validates every body and
prints only the fields asked for, or one line saying why not. It requires
exactly one zone named phasefinal.com and exactly one A record named
headscale.phasefinal.com, each with a non-empty id and content. Two A
records are refused rather than half-updated, and an empty id can no
longer shift the content into the id slot.
- No write without both IDs. The run ends on a confirmation that the record
now reads the new address. The previous final line was an echo whose exit
status was always 0, even when the parse inside it failed.
- Only a global unicast IPv4 is published (python ipaddress is_global).
Loopback, RFC1918, link-local, CGNAT and documentation ranges are retried
and then refused.
- curl -q as the first argument ignores ~/.curlrc, so a verbose config can
never log the bearer token. The vault CLI path is quoted. The empty
data-array expansion is safe under set -u on bash < 4.4.
Tests: services/headscale-ddns/test_headscale_ddns.py, 12 cases with curl,
the vault CLI and sleep stubbed. Each failure case asserts the FATAL line's
stated reason, so a run that died earlier for an unrelated cause cannot pass
it. The documentation-range fixtures (203.0.113.x) were themselves rejected
by the new public-IP guard: a free positive control.
Live: a manual run and a unit run both printed "unchanged 70.230.226.88",
Result=success. Cross-model bug-hunt (heid "Talus", Gróa + seat): all 8
findings folded.