Issues/Notes:
- Are there latency spikes that matter for auth or rec dns?
- NTP service might need some kernel params for more-accurate timekeeping: https://www.v13.gr/blog/?p=422
- Should we keep the combo role and do 3x dnsbox instances? or split this up somewhat? (it's convenient/reliable to have authdns on the same box as recdns for most query traffic, and they're all so low-load under normal conditions that minimizing the resource waste seems like a good idea... even VMs have per-instance costs).
- Public networking for edge ganetis is configured?