Add bind-external namespace for externally-reachable zones
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful

We self-delegate _acme-challenge.unkin.net into an acme.unkin.net zone we serve,
so cert-manager can solve Let's Encrypt DNS-01 over RFC2136/TSIG. That needs a
publicly-reachable authoritative BIND, separate from the internal estate.

- Add app bind-external (base + au-syd1 overlay) and register it in the platform
  ApplicationSet and AppProject destinations.
- Add BindCluster bind-external: authoritative-only, recursion off, no
  forwarding, transfers denied except the keyed catalog/zone AXFR; 2 replicas;
  primaryService is a dmz-pinned PureLB LoadBalancer (198.18.199.53).
- Add BindZone acme.unkin.net (primary, dynamicUpdate) and BindTSIGKey
  certmanager (hmac-sha256), whose Secret reflects into the cert-manager
  namespace for the rfc2136 solver.

Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
This commit is contained in:
Ben Vincent
2026-08-02 17:27:27 +10:00
parent 8d70149467
commit d6969ca390
8 changed files with 114 additions and 0 deletions
+19
View File
@@ -0,0 +1,19 @@
---
# Self-delegated ACME challenge zone. Google Cloud DNS holds a one-time
# _acme-challenge.unkin.net CNAME -> _acme-challenge.acme.unkin.net and an
# acme.unkin.net NS delegation pointing here; cert-manager writes the challenge
# TXT records via RFC2136 authenticated with the certmanager key.
apiVersion: bind.unkin.net/v1alpha1
kind: BindZone
metadata:
name: acme-unkin-net
namespace: bind-external
spec:
clusterRef: bind-external
zoneName: acme.unkin.net
type: primary
defaultTTL: 60
dynamicUpdate: true
updateKeyRef: certmanager
allowTransfer:
- key certmanager