# schlundtech-dns A command line tool for Schlundtech DNS. List your zones, inspect their records, and set them — from the terminal, no web interface. ## Build and run On the machine you develop on: ```bash go build ./schlundtech-dns --help ``` Or skip the binary entirely: ```bash go run . --help ``` > Use `go build`, not `go build ./...`. With more than one package the `...` > form only compiles and writes nothing. ### Build for a Linux server No toolchain on the target needed — the binary is pure Go and statically linked, so it runs on any Linux without a libc: ```bash CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -trimpath -ldflags "-s -w" \ -o dist/schlundtech-dns-linux-amd64 . ``` `GOARCH=arm64` gives you `dist/schlundtech-dns-linux-arm64`. Copy the file over and run it: ```bash ./schlundtech-dns-linux-amd64 --help ``` ## Configure Copy the example file and fill it in: ```bash cp .env.example .env chmod 600 .env $EDITOR .env ``` ```ini SCHLUNDTECH_USER=your-user SCHLUNDTECH_PASSWORD=your-password SCHLUNDTECH_CONTEXT=10 ``` Check that it works: ```bash ./schlundtech-dns zones ``` `.env` is read from the working directory. It is gitignored, and the tool warns if it is readable by other users. Real environment variables win over `.env`, so you can redirect a single invocation without editing the file: ```bash SCHLUNDTECH_CONTEXT=1 ./schlundtech-dns zones ``` **`SCHLUNDTECH_CONTEXT`** is the context ID Schlundtech gave you when you applied for gateway access. Every public implementation for Schlundtech uses `10`, so that is the value to try first — but yours is authoritative. The demo system uses `1`. **`SCHLUNDTECH_TOKEN`** — only if your account has two-factor authentication: the current six-digit code from your authenticator app. It is valid for about 30 seconds, so set it right before you run the command. **`SCHLUNDTECH_ENDPOINT`** — to talk to the demo system instead of your live zones: `https://demo.autodns.com/gateway/`. ## Use ### List your zones ```bash schlundtech-dns zones ``` ### Look at a zone's records ```bash schlundtech-dns records list example.com schlundtech-dns records list example.com --type TXT ``` ### Set a record ```bash schlundtech-dns records set example.com --name @ --type A --value 203.0.113.10 schlundtech-dns records set example.com --name @ --type TXT --value 'v=spf1 -all' ``` `@` is the zone apex, `www` would be `www.example.com`. `--ttl` defaults to the TTL the record already has. A name and type can hold several values — pass `--value` more than once. Setting any value replaces all existing ones for that name and type, so there is nothing to delete first. ### Dry run Every write touches public DNS and propagates within seconds. Preview first: ```bash schlundtech-dns records set example.com --name @ --type A --value 203.0.113.10 --dry-run ``` ### Remove a record Without `--value` this removes every value at that name and type: ```bash schlundtech-dns records delete example.com --name @ --type TXT --value 'v=spf1 -all' --dry-run schlundtech-dns records delete example.com --name @ --type TXT --value 'v=spf1 -all' ``` ### Pipe-friendly output Every command takes `--output table|json`. `table` is the default. ```bash schlundtech-dns records list example.com --output json | jq '.[].value' ``` Errors always go to stderr, so piping stdout stays clean. ## Record types There is no hardcoded list — `--type` takes whatever the gateway understands. TXT, A, AAAA, CNAME, MX and the rest all work the same way. Two notes: - `NS` and `SOA` are not worth touching. Changing them breaks zone delegation. - `MX` is managed by Schlundtech alongside their mail routing. Editing it by hand can break mail delivery for the domain. ## How it talks to the gateway The gateway is InterNetX's AutoDNS XML API, reached at `gateway.schlundtech.de`. Two things are worth knowing if you read the code: - **The gateway answers HTTP 200 even when a task fails.** The error is in the response body, not the status line. The tool parses the body and reads the error code from there; a non-2xx status only ever means a wrong path. - **A write is a remove and an add in one task.** Changing a record sends both halves together, so a rejected change leaves the zone untouched. The gateway allows three requests per second; the tool spaces its calls out accordingly. ## References - XML API basics: https://help.internetx.com/pages/viewpage.action?pageId=14878531 - Existing tools that speak the same gateway, useful for API details: [jurica/ddns-schlundtech](https://github.com/jurica/ddns-schlundtech), [couchtyp/certbot-dns-schlundtech](https://github.com/couchtyp/certbot-dns-schlundtech), [wosc/schlund-ddns](https://github.com/wosc/schlund-ddns)