Thanks. The glue format note is literally one line. "Use host.name.tld not just host." Would have saved me an hour.
Mini-guide: Using Cloudflare registrar with external DNS. The gotchas.
One line in docs, six hours in reality. Par for the course.
At Hetzner auction prices that 2TB is more like €25 now. The savings argument gets worse every year.
Still true at scale though. I run 40 domains for various projects. €320/year at Cloudflare vs €440 at Hetzner. €120 buys a lot of auction RAM.
For my association we have 6 domains. The saving is not worth the trouble. We stay at OVH. Their DNS is slow but predictable.
OVH had that fire in Strasbourg. Predictable until it is not.
I am at Gandi now. Expensive but the DNSSEC just works. No registry direct needed.
Strasbourg was 2021. Ancient history by cloud standards. OVH recovered fine.
This. Predictable is the word. These cloud registrar tricks cost you a Tuesday afternoon every six months.
The propagation delay is real. I just tested again with my smokeping setup. 18 minutes this time. API says success, edge says no.
Should be number 6 on your list. Or maybe it is the same bug manifesting differently.
Updated my notes. Thanks PollosHenry.
Consistent enough to be a real timeout somewhere in their pipeline. Not random.
How does this work with Cloudflare's own DNS? Same delay or instant? Thinking of moving everything to them instead of external.
Instant on their own DNS. The delay is only external providers. Something about the cross-account sync between registrar and the anycast edge.
I ran an ISP. This smells like two databases with eventual consistency and no read-after-write guarantee.