From aff06a633a2121f5cfda5e736c55beeb105c1297 Mon Sep 17 00:00:00 2001 From: Ben Vincent Date: Sat, 25 Jul 2026 23:53:55 +1000 Subject: [PATCH] Roll bind-operator to v0.2.6 (loop-free TSIG-keyed NOTIFY) (#293) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Deploy bind-operator v0.2.6 (bind-operator#15): NOTIFYs are now TSIG-signed via the catalog transfer key and secondaries accept by key, with no pod IPs in restart-scoped config — a regression test asserts the config-hash is invariant under pod IP churn, making the v0.2.5 roll-loop class impossible. Restores seconds-fast dynamic-zone propagation on bind-externaldns and bind-authoritative. - Bumps the operator image to git.unkin.net/unkin/bind-operator:v0.2.6 (confirmed in registry) - Bumps the CRD install pin to the v0.2.6 tag Expect exactly ONE settling roll of the bind statefulsets when the new config lands, then stability. Reviewed-on: https://git.unkin.net/unkin/argocd-apps/pulls/293 Co-authored-by: Ben Vincent Co-committed-by: Ben Vincent --- apps/base/bind-system/deployment.yaml | 2 +- apps/base/bind-system/kustomization.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/apps/base/bind-system/deployment.yaml b/apps/base/bind-system/deployment.yaml index 61c3866..8bb1eeb 100644 --- a/apps/base/bind-system/deployment.yaml +++ b/apps/base/bind-system/deployment.yaml @@ -21,7 +21,7 @@ spec: runAsNonRoot: true containers: - name: operator - image: git.unkin.net/unkin/bind-operator:v0.2.4 + image: git.unkin.net/unkin/bind-operator:v0.2.6 args: - --metrics-bind-address=:8080 - --health-probe-bind-address=:8081 diff --git a/apps/base/bind-system/kustomization.yaml b/apps/base/bind-system/kustomization.yaml index 5458594..453e5d6 100644 --- a/apps/base/bind-system/kustomization.yaml +++ b/apps/base/bind-system/kustomization.yaml @@ -6,7 +6,7 @@ resources: - namespace.yaml # CRDs are pulled from the bind-operator repo at the matching tag rather than # vendored here, so they never drift from the operator. - - https://git.unkin.net/unkin/bind-operator/raw/tag/v0.2.4/config/crd/install.yaml + - https://git.unkin.net/unkin/bind-operator/raw/tag/v0.2.6/config/crd/install.yaml - rbac.yaml - deployment.yaml - vpa.yaml