Temporarily forward k8s.syd1.au.unkin.net to external external-dns

The bind-resolvers forwarded k8s.syd1.au.unkin.net to the in-cluster
bind-externaldns (198.18.200.8), which is not reliably serving those
records yet, so lookups return NXDOMAIN. Notably Gitea cannot resolve the
k8s CI host, so its webhook fails and tagged releases (e.g. bind-operator)
never trigger CI.

Point the forwarder at the existing external external-dns bind service
anycast (198.18.19.20, puppet roles::infra::dns::externaldns), which still
holds the working records. Temporary; revert to 198.18.200.8 once
external-dns publishes to the in-cluster service.
This commit is contained in:
2026-07-21 00:11:48 +10:00
parent 0c1156282f
commit 34e8c80d49
@@ -1,6 +1,12 @@
# Conditional forward zones, from the puppet openforwarder view.
# Upstreams: unkin authoritative 198.18.200.6, consul 198.18.19.14, k8s 198.18.200.8.
# k8s -> in-cluster bind-externaldns 198.18.200.8.
# Upstreams: unkin authoritative 198.18.200.6, consul 198.18.19.14.
# k8s -> TEMPORARY: the existing external external-dns bind service anycast
# 198.18.19.20 (puppet roles::infra::dns::externaldns, ausyd1nxvm2127 + slaves),
# NOT the in-cluster bind-externaldns 198.18.200.8. The external service still
# holds the working k8s.syd1.au.unkin.net records; the in-cluster one is not
# reliably serving them yet, so forwarding there returns NXDOMAIN (which
# currently breaks Gitea's CI webhook: it cannot resolve the k8s CI host).
# Revert to 198.18.200.8 once external-dns publishes to the in-cluster service.
# (Zones that forwarded to 10.10.16.x were dropped; consul left as-is.)
---
apiVersion: bind.unkin.net/v1alpha1
@@ -57,7 +63,10 @@ spec:
type: forward
catalog: false
forwarders:
- 198.18.200.8
# TEMPORARY: existing external external-dns bind service anycast, which
# currently holds the k8s.syd1.au.unkin.net records. Revert to 198.18.200.8
# (in-cluster bind-externaldns) once external-dns publishes there.
- 198.18.19.20
---
apiVersion: bind.unkin.net/v1alpha1
kind: BindZone