diff --git a/apps/base/bind-internal/resolvers/forward-zones.yaml b/apps/base/bind-internal/resolvers/forward-zones.yaml index c4c8e82..5e18a34 100644 --- a/apps/base/bind-internal/resolvers/forward-zones.yaml +++ b/apps/base/bind-internal/resolvers/forward-zones.yaml @@ -1,6 +1,12 @@ # Conditional forward zones, from the puppet openforwarder view. -# Upstreams: unkin authoritative 198.18.200.6, consul 198.18.19.14, k8s 198.18.200.8. -# k8s -> in-cluster bind-externaldns 198.18.200.8. +# Upstreams: unkin authoritative 198.18.200.6, consul 198.18.19.14. +# k8s -> TEMPORARY: the existing external external-dns bind service anycast +# 198.18.19.20 (puppet roles::infra::dns::externaldns, ausyd1nxvm2127 + slaves), +# NOT the in-cluster bind-externaldns 198.18.200.8. The external service still +# holds the working k8s.syd1.au.unkin.net records; the in-cluster one is not +# reliably serving them yet, so forwarding there returns NXDOMAIN (which +# currently breaks Gitea's CI webhook: it cannot resolve the k8s CI host). +# Revert to 198.18.200.8 once external-dns publishes to the in-cluster service. # (Zones that forwarded to 10.10.16.x were dropped; consul left as-is.) --- apiVersion: bind.unkin.net/v1alpha1 @@ -57,7 +63,10 @@ spec: type: forward catalog: false forwarders: - - 198.18.200.8 + # TEMPORARY: existing external external-dns bind service anycast, which + # currently holds the k8s.syd1.au.unkin.net records. Revert to 198.18.200.8 + # (in-cluster bind-externaldns) once external-dns publishes there. + - 198.18.19.20 --- apiVersion: bind.unkin.net/v1alpha1 kind: BindZone