feat(bind-internal): publish haproxy edge sites from k8s DNS (#523)

The VM haproxies are being decommissioned; the sites they published via puppet CNAMEs are already served by the k8s haproxy edge, so k8s DNS publishes them instead.

- add main.unkin.net A records for sonarr, radarr, lidarr, readarr, prowlarr, nzbget, jellyfin -> 198.18.199.0
- add unkin.net A records for fafflix and git (git-edge.yaml) -> 198.18.199.0, auth -> 198.18.200.4
- point the commented git.yaml cutover at replacing git-edge.yaml

Merge alongside puppet-prod halb DNS removal; A records only take effect once the puppet CNAMEs are gone.

Reviewed-on: #523
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #523.
This commit is contained in:
2026-10-05 01:31:06 +11:00
committed by BenVincent
parent d9cc24dbdb
commit 6d842c7d66
15 changed files with 167 additions and 9 deletions
@@ -11,5 +11,6 @@ resources:
- tsigkey.yaml
- zones.yaml
- unkin-net
- main-unkin-net
- ceph-unkin-net
- acls.yaml
@@ -0,0 +1,14 @@
---
apiVersion: bind.unkin.net/v1alpha1
kind: DNSRecord
metadata:
name: jellyfin-dns-internal
namespace: bind-internal
spec:
zoneRef: main-unkin-net
name: jellyfin
type: A
ttl: 600
values:
# traefik-external haproxy edge Gateway VIP (TLS passthrough).
- 198.18.199.0
@@ -0,0 +1,12 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- jellyfin.yaml
- lidarr.yaml
- nzbget.yaml
- prowlarr.yaml
- radarr.yaml
- readarr.yaml
- sonarr.yaml
@@ -0,0 +1,14 @@
---
apiVersion: bind.unkin.net/v1alpha1
kind: DNSRecord
metadata:
name: lidarr-dns-internal
namespace: bind-internal
spec:
zoneRef: main-unkin-net
name: lidarr
type: A
ttl: 600
values:
# traefik-external haproxy edge Gateway VIP (TLS passthrough).
- 198.18.199.0
@@ -0,0 +1,14 @@
---
apiVersion: bind.unkin.net/v1alpha1
kind: DNSRecord
metadata:
name: nzbget-dns-internal
namespace: bind-internal
spec:
zoneRef: main-unkin-net
name: nzbget
type: A
ttl: 600
values:
# traefik-external haproxy edge Gateway VIP (TLS passthrough).
- 198.18.199.0
@@ -0,0 +1,14 @@
---
apiVersion: bind.unkin.net/v1alpha1
kind: DNSRecord
metadata:
name: prowlarr-dns-internal
namespace: bind-internal
spec:
zoneRef: main-unkin-net
name: prowlarr
type: A
ttl: 600
values:
# traefik-external haproxy edge Gateway VIP (TLS passthrough).
- 198.18.199.0
@@ -0,0 +1,14 @@
---
apiVersion: bind.unkin.net/v1alpha1
kind: DNSRecord
metadata:
name: radarr-dns-internal
namespace: bind-internal
spec:
zoneRef: main-unkin-net
name: radarr
type: A
ttl: 600
values:
# traefik-external haproxy edge Gateway VIP (TLS passthrough).
- 198.18.199.0
@@ -0,0 +1,14 @@
---
apiVersion: bind.unkin.net/v1alpha1
kind: DNSRecord
metadata:
name: readarr-dns-internal
namespace: bind-internal
spec:
zoneRef: main-unkin-net
name: readarr
type: A
ttl: 600
values:
# traefik-external haproxy edge Gateway VIP (TLS passthrough).
- 198.18.199.0
@@ -0,0 +1,14 @@
---
apiVersion: bind.unkin.net/v1alpha1
kind: DNSRecord
metadata:
name: sonarr-dns-internal
namespace: bind-internal
spec:
zoneRef: main-unkin-net
name: sonarr
type: A
ttl: 600
values:
# traefik-external haproxy edge Gateway VIP (TLS passthrough).
- 198.18.199.0
@@ -0,0 +1,6 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- a
@@ -0,0 +1,14 @@
---
apiVersion: bind.unkin.net/v1alpha1
kind: DNSRecord
metadata:
name: auth-dns-internal
namespace: bind-internal
spec:
zoneRef: unkin-net
name: auth
type: A
ttl: 600
values:
# traefik-internal gateway VIP; the kanidm Gateway serves auth.unkin.net there.
- 198.18.200.4
@@ -0,0 +1,14 @@
---
apiVersion: bind.unkin.net/v1alpha1
kind: DNSRecord
metadata:
name: fafflix-dns-internal
namespace: bind-internal
spec:
zoneRef: unkin-net
name: fafflix
type: A
ttl: 600
values:
# traefik-external haproxy edge Gateway VIP (TLS passthrough).
- 198.18.199.0
@@ -0,0 +1,14 @@
---
apiVersion: bind.unkin.net/v1alpha1
kind: DNSRecord
metadata:
name: git-edge-dns-internal
namespace: bind-internal
spec:
zoneRef: unkin-net
name: git
type: A
ttl: 600
values:
# traefik-external haproxy edge Gateway VIP (TLS passthrough).
- 198.18.199.0
@@ -1,16 +1,12 @@
---
# PRODUCTION CUTOVER RECORD — intentionally commented out.
# git.unkin.net currently resolves to the LIVE VM forge (HAProxy VRRP VIP
# 198.18.19.17), which holds every repo the estate depends on. Uncommenting this
# git.unkin.net currently resolves to the haproxy edge (git-edge.yaml), which
# forwards to the LIVE VM forge holding every repo. Uncommenting this
# repoints the whole org's git.unkin.net at the new k8s Gitea gateway VIP, so it
# is the FINAL step of the forge migration — gated on the data migration (gitea
# dump/restore + SECRET_KEY copy) in argocd-apps docs/gitea-migration.md.
# NOTE: the live git.unkin.net answer is served by the puppet DNS master today
# (profiles::dns::master, records from PuppetDB); this k8s apex zone holds only
# SOA+NS + a few DNSRecords so far. Confirm the k8s bind cluster is the live
# authority for unkin.net (or update the puppet record instead) before relying
# on this CR at cutover.
# Uncomment this record AND its entry in kustomization.yaml to activate it.
# Uncomment this record AND its entry in kustomization.yaml (removing
# git-edge.yaml there) to activate it.
# ---
# apiVersion: bind.unkin.net/v1alpha1
# kind: DNSRecord
@@ -4,11 +4,14 @@ kind: Kustomization
resources:
- arrstack.yaml
- auth.yaml
- cheeztv.yaml
- fafflix.yaml
# PRODUCTION CUTOVER RECORD — see git.yaml. Uncomment together with the
# record itself.
# record itself, and remove git-edge.yaml.
# - git.yaml
- ghp.yaml
- git-edge.yaml
- grafana.yaml
- identity.yaml
- lb1.yaml