+// Unfortunately, AFAICT we need to list the Linode IPs as an ACL (so they
+// can make the requests) *and* as masters (so they get the notify).
+acl "linode" {
+ // Linode
+ // https://www.linode.com/docs/products/networking/dns-manager/guides/incoming-dns-zone-transfers/#operate-as-a-secondary-read-only-dns-service
+ 104.237.137.10;
+ 45.79.109.10;
+ 74.207.225.10;
+ 207.192.70.10;
+ 109.74.194.10;
+ 2600:3c00::a;
+ 2600:3c01::a;
+ 2600:3c02::a;
+ 2600:3c03::a;
+ 2a01:7e00::a;
+ // Import
+ // https://www.linode.com/docs/products/networking/dns-manager/guides/incoming-dns-zone-transfers/#import-a-dns-zone
+ 96.126.114.97;
+ 96.126.114.98;
+ 2600:3c00::5e;
+ 2600:3c00::5f;
+};
+
+masters "linode" {
+ // Linode
+ // https://www.linode.com/docs/products/networking/dns-manager/guides/incoming-dns-zone-transfers/#operate-as-a-secondary-read-only-dns-service
+ 104.237.137.10;
+ 45.79.109.10;
+ 74.207.225.10;
+ 207.192.70.10;
+ 109.74.194.10;
+ 2600:3c00::a;
+ 2600:3c01::a;
+ 2600:3c02::a;
+ 2600:3c03::a;
+ 2a01:7e00::a;
+ // Import
+ // https://www.linode.com/docs/products/networking/dns-manager/guides/incoming-dns-zone-transfers/#import-a-dns-zone
+ 96.126.114.97;
+ 96.126.114.98;
+ 2600:3c00::5e;
+ 2600:3c00::5f;
+};
+
+// The actual ACL building blocks