216b1d72ac
records.yaml had grown to ten DNSRecord documents across two zones, so finding or reviewing a single record meant scanning the whole file and every change touched it. - move each record to authoritative/<zone>/<type>/<record>.yaml - add a kustomization.yaml per zone and per type directory - keep the git.unkin.net cutover record commented out, alongside a commented kustomization entry - move the DNSRecord-namespace rationale onto the authoritative kustomization - delete records.yaml Rendered output is unchanged. Reviewed-on: #501 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
18 lines
460 B
YAML
18 lines
460 B
YAML
---
|
|
apiVersion: bind.unkin.net/v1alpha1
|
|
kind: DNSRecord
|
|
metadata:
|
|
# "internal" in the name distinguishes this from the external DNS that
|
|
# Authentik will manage its own records from later.
|
|
name: identity-dns-internal
|
|
namespace: bind-internal
|
|
spec:
|
|
zoneRef: unkin-net
|
|
name: identity
|
|
type: A
|
|
ttl: 600
|
|
values:
|
|
# traefik-EXTERNAL (DMZ) gateway VIP; the authentik Gateway serves the
|
|
# identity.unkin.net hostname there.
|
|
- 198.18.199.0
|