--- # Externally-reachable authoritative BIND for zones we delegate to ourselves. # First tenant: acme.unkin.net, the DNS-01 challenge zone Let's Encrypt validates # via a one-time _acme-challenge.unkin.net CNAME. Authoritative-only, recursion # off, no forwarding, no open transfers -- the primaryService is the single # dmz-pinned LoadBalancer that public NAT targets and that cert-manager writes to. apiVersion: bind.unkin.net/v1alpha1 kind: BindCluster metadata: name: bind-external namespace: bind-external spec: mode: authoritative recursion: false replicas: 2 storageClassName: cephrbd-fast-delete storageSize: 1Gi # Public server: answer queries from anywhere (Let's Encrypt validates over the # internet), deny recursion and open zone transfers. localhost + pod net are # implied by "any" and cover in-pod nsupdate and secondary SOA refresh; per-zone # allow-transfer (catalog + acme zone) still permits key-authenticated AXFR. extraOptions: - "allow-query { any; }" - "allow-transfer { none; }" service: type: ClusterIP primaryService: type: LoadBalancer externalTrafficPolicy: Local annotations: purelb.io/service-group: dmz purelb.io/addresses: 198.18.199.53 external-dns.alpha.kubernetes.io/hostname: bind-external-primary.k8s.syd1.au.unkin.net resources: requests: cpu: 20m memory: 128Mi limits: cpu: "1" memory: 512Mi --- # Catalog zone so the acme zone replicates onto the secondary (AXFR/IXFR keyed # with the certmanager TSIG key, reused here as the transfer key). apiVersion: bind.unkin.net/v1alpha1 kind: BindCatalogZone metadata: name: bind-external-catalog namespace: bind-external spec: clusterRef: bind-external zoneName: catalog.external transferKeyRef: certmanager