RE: https://hachyderm.io/@zrail/116053772428911398
So I think I solved... half(?) the problem. It dawned on me that I can use any machine on a given network to announce an #ipv6 prefix and as long as it has the router lifetime set to 0 no clients will try to use it as a gateway.
Thus, I'm announcing a /64 slice of the /48 I leased from a tiny lxc running on my N100 "critical stuff" machine.
I think for DNS I'm going to just put these addresses in public DNS. The whole point is that they're static and one fewer moving piece is nice. This doesn't solve the "but what if internet is down" problem but I don't think that's super realistic.
Oh one other thing worth mentioning: this /64 is not routed. From the outside it'll hit the blackhole route on my router VPS.
