Repoint external-dns at the in-cluster bind-externaldns primary
Step 2 of the external-dns → in-cluster bind migration. external-dns stops sending RFC2136 updates to the legacy VM (ausyd1nxvm2127.main.unkin.net) and targets the in-cluster bind-externaldns primary Service, reading the reflected operator-generated TSIG key. - Point --rfc2136-host at bind-externaldns-primary.bind-internal.svc.cluster.local (ClusterIP Service, verified live). - Read the TSIG secret + algorithm from externaldns-key-tsig (reflected by PR 1) instead of the Vault-backed externaldns-tsig Secret. - Keep port, zones, keyname, txtOwnerId, and the old Vault manifests unchanged; the Vault secret stays as a rollback path and is removed in a later cleanup PR.
This commit is contained in:
@@ -27,22 +27,24 @@ sources:
|
|||||||
- gateway-httproute
|
- gateway-httproute
|
||||||
- gateway-grpcroute
|
- gateway-grpcroute
|
||||||
|
|
||||||
# Environment variables for TSIG secret and algorithm from Vault
|
# TSIG secret + algorithm. The bind operator generates this key in
|
||||||
|
# bind-internal (BindTSIGKey externaldns-key) and the emberstack reflector
|
||||||
|
# mirrors the Secret into this namespace as externaldns-key-tsig.
|
||||||
env:
|
env:
|
||||||
- name: EXTERNAL_DNS_RFC2136_TSIG_SECRET
|
- name: EXTERNAL_DNS_RFC2136_TSIG_SECRET
|
||||||
valueFrom:
|
valueFrom:
|
||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
name: externaldns-tsig
|
name: externaldns-key-tsig
|
||||||
key: secret
|
key: secret
|
||||||
- name: EXTERNAL_DNS_RFC2136_TSIG_ALGORITHM
|
- name: EXTERNAL_DNS_RFC2136_TSIG_ALGORITHM
|
||||||
valueFrom:
|
valueFrom:
|
||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
name: externaldns-tsig
|
name: externaldns-key-tsig
|
||||||
key: algorithm
|
key: algorithm
|
||||||
|
|
||||||
# RFC2136 configuration as arguments
|
# RFC2136 configuration as arguments
|
||||||
extraArgs:
|
extraArgs:
|
||||||
- --rfc2136-host=ausyd1nxvm2127.main.unkin.net
|
- --rfc2136-host=bind-externaldns-primary.bind-internal.svc.cluster.local
|
||||||
- --rfc2136-port=53
|
- --rfc2136-port=53
|
||||||
- --rfc2136-zone=k8s.syd1.au.unkin.net
|
- --rfc2136-zone=k8s.syd1.au.unkin.net
|
||||||
- --rfc2136-zone=200.18.198.in-addr.arpa
|
- --rfc2136-zone=200.18.198.in-addr.arpa
|
||||||
|
|||||||
Reference in New Issue
Block a user