From 148dac8ca23cd8f9c08af690f9f5bdabfc4ccf95 Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Sun, 27 Sep 2026 00:10:13 +1000 Subject: [PATCH] Declare the acme.unkin.net nameservers (#495) The zone was seeded with an apex `NS ns1.acme.unkin.net` glued to the primary pod IP. Both were later corrected by hand, so the live RRset and the ns1 address exist only in the zone journal -- a reseed republishes the pod IP and breaks DNS-01 for every `*.unkin.net` cert. Declaring them makes git the source of truth. - declare the two published apex NS names - declare the in-zone ns1 address, which a seed would otherwise glue to the pod IP Matches what the zone serves today, so applying it changes no records. Requires bind-operator v0.3.0. Reviewed-on: https://git.unkin.net/unkin/argocd-apps/pulls/495 Co-authored-by: unkin-agent Co-committed-by: unkin-agent --- apps/base/bind-external/zones.yaml | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/apps/base/bind-external/zones.yaml b/apps/base/bind-external/zones.yaml index 05ece86..d252a60 100644 --- a/apps/base/bind-external/zones.yaml +++ b/apps/base/bind-external/zones.yaml @@ -17,3 +17,14 @@ spec: updateKeyRef: certmanager allowTransfer: - key certmanager + # Published apex NS. acme-ns1 is what the parent delegates to and glues; ns1 is + # in-zone, so its address is declared below or a reseed would glue it to the + # primary pod IP. + nameservers: + - acme-ns1.unkin.net. + - ns1.acme.unkin.net. + records: + - name: ns1 + type: A + ttl: 3600 + values: ["103.216.191.185"]