From 513c60492b30e204f94aded8d6eeac23e0f38e2e Mon Sep 17 00:00:00 2001 From: Ben Vincent Date: Sat, 18 Jul 2026 16:30:23 +1000 Subject: [PATCH] bind-internal: add s3.ceph.unkin.net CNAME -> radosgw.service.consul (#265) ## Why Publish the RGW S3 endpoint name (`s3.ceph.unkin.net`) that cephrgw-operator consumers use and that the radosgw hosts will carry as a cert SAN. For now it points at the Consul service; the real target will be changed later. ## Changes - Add a `DNSRecord` in the `ceph.unkin.net` authoritative zone: `s3` CNAME `radosgw.service.consul.` (`apps/base/bind-internal/authoritative/records.yaml`, zoneRef `ceph-unkin-net`, TTL 600). A companion puppet-prod change adds `s3.ceph.unkin.net` to the radosgw cert SANs and nginx server names. --------- Co-authored-by: benvin Reviewed-on: https://git.unkin.net/unkin/argocd-apps/pulls/265 Co-authored-by: Ben Vincent Co-committed-by: Ben Vincent --- .../base/bind-internal/authoritative/records.yaml | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/apps/base/bind-internal/authoritative/records.yaml b/apps/base/bind-internal/authoritative/records.yaml index d4bb741..32e1cfa 100644 --- a/apps/base/bind-internal/authoritative/records.yaml +++ b/apps/base/bind-internal/authoritative/records.yaml @@ -19,3 +19,18 @@ spec: # traefik-internal gateway VIP; the authentik Gateway serves the # identity.unkin.net hostname there. - 198.18.200.4 +--- +apiVersion: bind.unkin.net/v1alpha1 +kind: DNSRecord +metadata: + name: s3-ceph-cname + namespace: bind-internal +spec: + zoneRef: ceph-unkin-net + name: s3 + type: CNAME + ttl: 600 + values: + # radosgw S3 endpoint. Points at the Consul service for now; the real + # target will be changed later. + - radosgw.service.consul.