Great subject matter that is not written about enough. You addressed the issue with the Internal versus External namespace matter, and while your recommendations are sound (single namespace, split-brain DNS), one of the challenges is that recommendation is great for green-field deployments, but does not help the organization that has an existing namespace topology that doesn't fall under the single namespace, subdomain approach. There are a ton of .Loc or other internal TLDs that are not owned by the organization, or was an artifact of some earlier acquisition, or just reflecting practices in the late 1990's. Many of these folks feel stuck as to how to approach. I would love to hear your comments on the strategies not for greenfield environments, but legacy environments that have to deal with these matters.
Thanks,
http://vmpete.com
@vmpete