Repoint external-dns at the in-cluster bind-externaldns primary
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful

Step 2 of the external-dns → in-cluster bind migration. external-dns stops
sending RFC2136 updates to the legacy VM (ausyd1nxvm2127.main.unkin.net) and
targets the in-cluster bind-externaldns primary Service, reading the reflected
operator-generated TSIG key.

- Point --rfc2136-host at bind-externaldns-primary.bind-internal.svc.cluster.local
  (ClusterIP Service, verified live).
- Read the TSIG secret + algorithm from externaldns-key-tsig (reflected by PR 1)
  instead of the Vault-backed externaldns-tsig Secret.
- Keep port, zones, keyname, txtOwnerId, and the old Vault manifests unchanged;
  the Vault secret stays as a rollback path and is removed in a later cleanup PR.
This commit is contained in:
2026-07-25 22:34:16 +10:00
parent 1d87c42fc1
commit c353fa797b
@@ -27,22 +27,24 @@ sources:
- gateway-httproute
- gateway-grpcroute
# Environment variables for TSIG secret and algorithm from Vault
# TSIG secret + algorithm. The bind operator generates this key in
# bind-internal (BindTSIGKey externaldns-key) and the emberstack reflector
# mirrors the Secret into this namespace as externaldns-key-tsig.
env:
- name: EXTERNAL_DNS_RFC2136_TSIG_SECRET
valueFrom:
secretKeyRef:
name: externaldns-tsig
name: externaldns-key-tsig
key: secret
- name: EXTERNAL_DNS_RFC2136_TSIG_ALGORITHM
valueFrom:
secretKeyRef:
name: externaldns-tsig
name: externaldns-key-tsig
key: algorithm
# RFC2136 configuration as arguments
extraArgs:
- --rfc2136-host=ausyd1nxvm2127.main.unkin.net
- --rfc2136-host=bind-externaldns-primary.bind-internal.svc.cluster.local
- --rfc2136-port=53
- --rfc2136-zone=k8s.syd1.au.unkin.net
- --rfc2136-zone=200.18.198.in-addr.arpa