{"actions":{"bootstrapAndRun":{"effect":"installs rote if missing, inspects, prepares, and asks before running","href":"https://play.modiqo.ai/install?play=himanshu-jha/dns-zone-integrity@0.1.0","method":"GET","rel":"https://rote.dev/rels/bootstrap-and-run","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"inspect":{"command":"rote play inspect https://play.modiqo.ai/himanshu-jha/dns-zone-integrity@0.1.0","effect":"read-only"},"installCliOnly":{"effect":"installs the rote CLI, nothing else","href":"https://play.modiqo.ai/install","method":"GET","rel":"https://rote.dev/rels/install-cli","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"run":{"command":"rote play run https://play.modiqo.ai/himanshu-jha/dns-zone-integrity@0.1.0","effect":"executes the play locally after consent","headless":{"approvalAssertion":"--yes","approvalRequiredBeforeInvocation":true,"commandTemplate":"rote play run https://play.modiqo.ai/himanshu-jha/dns-zone-integrity@0.1.0 <name=value...> --yes","stdinPolicy":"never pipe input to automate the interactive Ready selector"},"requiresConsent":true}},"description":"Analyzes a normalized DNS zone snapshot as interacting RRsets and graph boundaries. Use it before every zone deployment and during DNS incident triage. Nonblank record owners/types/values, supported SOA/NS/MX/SRV/name-bearing RDATA shapes, and a finite ordered TTL policy are validated before RRsets can satisfy coverage; name-bearing RDATA is then resolved against the zone before semantic duplicate or conflict checks, so relative and equivalent absolute targets compare identically while non-name payload case remains intact. Four sibling probes detect CNAME/apex/SOA/RRset conflicts (including multi-target CNAME owners), dangling or cyclic in-zone targets with linear bounded-witness traversal and MX/SRV/NS targets that illegally alias through CNAME, broken delegation/glue/DS boundaries, and TTL incoherence across RRsets and alias chains; a synthesis join produces one integrity verdict with severity-prioritized repairs. It reads JSON only, performs no DNS queries or zone changes, and writes nothing. Run with inpu","distribution":{"digest":"sha256:8d929714f4deaeb8881714bc1624bc07dcbedc9cfcbaaca68297b318864c2790","mediaType":"application/vnd.modiqo.rote-flow","size":14830,"verifiedBy":"rote verifies the downloaded archive against this digest before it runs"},"effects":{"credentialsProvidedBy":"runner","credentialsRemainLocal":true,"declaredWrites":[],"publisherReceivesCredentials":false},"id":"https://play.modiqo.ai/himanshu-jha/dns-zone-integrity@0.1.0","inputPolicy":{"optionalWithDefault":"show_default_and_accept_override","optionalWithoutDefault":"omit_unless_supplied","required":"ask","secrets":"collect_locally_outside_conversation"},"license":"MIT","links":{"docs":"https://rote.dev","page":"https://play.modiqo.ai/himanshu-jha/dns-zone-integrity@0.1.0","protocol":"https://play.modiqo.ai/.well-known/rote","self":"https://play.modiqo.ai/himanshu-jha/dns-zone-integrity@0.1.0.json"},"name":"dns-zone-integrity","owner":{"kind":"org","slug":"himanshu-jha"},"parameters":[{"description":"Workspace-relative normalized zone JSON. Omit for the bundled demo; pass input=zones/example-com.json for fresh zone evidence.","example":"zones/example-com.json","input":{"allowCustom":true,"choices":[],"label":"Input"},"name":"input","required":false,"type":"string"}],"preparation":[{"action":{"command":"rote play inspect https://play.modiqo.ai/himanshu-jha/dns-zone-integrity@0.1.0 --json","effect":"read-only"},"step":1,"type":"inspect_local_readiness"},{"references":["/parameters"],"step":2,"type":"collect_parameters"},{"references":["/parameters","/requirements","/effects"],"step":3,"type":"review"},{"consentBoundary":"the user approves the exact play and parameter values","references":["/parameters","/requirements","/effects"],"step":4,"type":"obtain_run_consent"},{"action":{"command":"rote play run https://play.modiqo.ai/himanshu-jha/dns-zone-integrity@0.1.0","headlessCommandTemplate":"rote play run https://play.modiqo.ai/himanshu-jha/dns-zone-integrity@0.1.0 <name=value...> --yes"},"preservesAcquisitionBoundaries":["adapter_selection","oauth_dcr","google_discovery","static_token_setup","runtime_security_checks"],"requiresConsent":true,"step":5,"type":"run"}],"producedBy":{"roteVersion":"0.78.0"},"publishedAt":"2026-09-04T12:24:50.822038+00:00","reference":"himanshu-jha/dns-zone-integrity@0.1.0","requirements":{"adapters":[],"browser":{"dependencies":[],"runtime":false,"signIn":false},"localTools":["python3"],"roteCli":{"minimumVersion":"0.62.0"},"sessions":false},"resolution":"pinned","schema":"rote.play.v1","stats":{"downloads":2,"installs":0},"steps":{"count":5,"names":["analyze_ttl_coherence","audit_delegation_boundaries","detect_rrset_conflicts","prove_target_graph_closure","synthesize_zone_integrity"]},"title":"dns-zone-integrity","type":"play","version":"0.1.0","visibility":"public"}