blackreset.com — managed at Hetzner Cloud DNS10.100.0.10 — in Migration nach 10.100.100.10 (Proxmox HM) resolves internal*.blackreset.local (exact zone name TBD on AD discovery)https://api.hetzner.cloud/v1/zones, Bearer token (64-char Cloud token)HETZNER_DNS__API_TOKEN (für DNS) bzw. HETZNER_CLOUD__API_TOKEN (für Cloud-API) in .secrets/credentials.env| Record | Target | Service |
|---|---|---|
wiki.blackreset.com |
RZ public IP (via Traefik on VM-SL-00) | Wiki.js |
auth.blackreset.com |
RZ public IP (via Traefik) | Authentik |
mail.blackreset.com |
VM-SL-02 (Mailcow) | Mailcow |
autodiscover.blackreset.com |
VM-SL-02 | Mailcow autodiscover |
autoconfig.blackreset.com |
VM-SL-02 | Mailcow autoconfig |
(Full inventory pending — Authentik's OAuth2 application list mirrors much
of the public-facing surface; see Access / Authentik.)
Single AD DC at 10.100.0.10 is the authoritative resolver for the internal
zone. Documented as an accepted SPoF.
Cleanup-Hinweis 2026-05-04: Hetzner DNS API Reference siehe /reference/hetzner-dns-api.