<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>NodeJS on Mexicali IT</title><link>https://mxlit.com/technologies/nodejs/</link><description>Recent content in NodeJS on Mexicali IT</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 03 Aug 2026 00:30:53 -0700</lastBuildDate><atom:link href="https://mxlit.com/technologies/nodejs/index.xml" rel="self" type="application/rss+xml"/><item><title>Cloudflare: Building a Zero-Trust, Self-Hosted DNS Manager</title><link>https://mxlit.com/kb-00097/</link><pubDate>Mon, 03 Aug 2026 00:30:53 -0700</pubDate><guid>https://mxlit.com/kb-00097/</guid><description>&lt;p&gt;Managing DNS records for your personal domain or homelab can quickly become tedious if you have to constantly log into the official Cloudflare dashboard. Plus, the official dashboard exposes all your critical domain records (such as TXT, MX, DKIM, DMARC), which makes it easy to accidentally delete or modify something important.&lt;/p&gt;&#10;&lt;p&gt;Additionally, there was the challenge of keeping the &lt;code&gt;A&lt;/code&gt; records pointing to homelab services updated under a dynamic public IP address (provided by my ISP). For years, I relied on the built-in DDNS client of my Sophos firewall for this task. However, it suddenly stopped working recently because Sophos requires authentication using the Cloudflare &lt;strong&gt;Global API Key&lt;/strong&gt; (along with the account email). Cloudflare has deprecated this legacy method and now recommends using &lt;strong&gt;API Tokens&lt;/strong&gt;. Handing over your Global API Key (which basically gives full control over your entire Cloudflare account) to a third-party appliance is simply no longer a good security practice.&lt;/p&gt;</description></item></channel></rss>