Skip to content

Network

ernolf edited this page Sep 25, 2026 · 1 revision

The example network

Every page in this wiki explains dcm against one and the same setup. It is fictional — no machine, address or domain listed here exists — but it has the shape dcm was built for, so instead of inventing fresh placeholders per page, each page refers back to this one.

Substitute your own names and addresses; nothing in dcm depends on any of them.

The two dcm nodes

castor and pollux, the twins of Greek myth: two interchangeable machines holding the identical configuration, one listen address apart. That is the whole idea of dcm.

Host Address Role
castor 192.168.189.1 DNS master, and the one node that serves the web UI (Apache2 + PHP-FPM)
pollux 192.168.189.101 DNS replica

Both stand in the Frankfurt network below, whose /23 reaches from 192.168.188.0 to 192.168.189.255; the two servers use its upper half. Every client at every site asks both of them, so either one can be down.

The four virtual machines

Four VMs on a laptop that travels between the sites, named after crew members of the Argo — the ship the twins sailed on. Each keeps a fixed last octet, so only the prefix changes when the laptop comes up in another network, and the name resolves everywhere.

VM Host part At Berlin 1 At Berlin 2
iason .40 192.168.78.40 10.1.10.40
orpheus .50 192.168.78.50 10.1.10.50
atalante .84 192.168.78.84 10.1.10.84
hylas .85 192.168.78.85 10.1.10.85

That prefix rewrite is what the relocation button on the VMs page does — see Hosts files.

The five networks

Four fixed lines — branch offices, or flats of the same family — plus one mobile network. Each site runs a Fritzbox as its router and DHCP server, and hands out castor and pollux as the DNS servers.

Site Router Network
Frankfurt Fritzbox 7580 192.168.188.0/23 gateway site, hosts castor and pollux
Berlin 1 Fritzbox 7690 192.168.78.0/24
Zürich Fritzbox 5530 Fiber 192.168.118.0/24
Berlin 2 Fritzbox 7430 10.1.10.0/24
Mobile Fritzbox 6820 LTE 192.168.178.0/24 dials into Frankfurt, one direction only

The four fixed lines are joined by a full mesh of VPN tunnels. The mobile router is not part of that mesh: a mobile network hands out no real external address, so its tunnel only works in one direction, dialled from the router into the gateway site. That is enough for what dcm needs — the router gets an address in the gateway network, its own web interface is reachable from there, and it resolves through castor and pollux like every other site, which puts all of example.net within reach through that single tunnel. What does not work is the other direction: devices behind the mobile router cannot be reached from the other sites, and it has no tunnels to Berlin 1, Berlin 2 or Zürich at all.

The domain

example.net stands in for your own domain. dcm answers it locally, and the names the wiki uses are:

Name What it is
dns.example.net the dcm web interface, on castor
dcm.example.net an alias for the same vhost
adblock.example.net the sink that ad-server names are pointed at

The UI node must never be reachable from the internet, so it cannot answer an ACME HTTP-01 challenge. The example therefore assumes a wildcard certificate for *.example.net, issued over a DNS-01 challenge — obtained on a host that manages the domain's DNS, and copied to castor. See Installation, step 6.

Where this shows up

  • Architecture — the network diagram, the query path and the sync flow
  • Installation — castor is the UI node, pollux the second node
  • Hosts files — the node entries that generate each listen.conf, and the VM relocation

dcm

Getting started

Managing the cluster

Under the hood

What comes next

Clone this wiki locally