a5a5cc44e9
bind-operator v0.3.1 fixes the apex NS bug two ways: the operator no longer glues apex NS records to pod IPs, and a new CEL rule on `DNSRecordSpec` rejects apex NS DNSRecords at admission. The CRDs are pinned by tag URL, so bumping only the image would leave the admission half inert. - Bump the bind-operator image to `v0.3.1` - Bump the CRD install URL to the matching `v0.3.1` tag --------- Co-authored-by: unkin-agent <unkin-agent@unkin.net> Reviewed-on: #503 Co-authored-by: Ben Vincent <ben@unkin.net> Co-committed-by: Ben Vincent <ben@unkin.net>
14 lines
393 B
YAML
14 lines
393 B
YAML
---
|
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
kind: Kustomization
|
|
|
|
resources:
|
|
- namespace.yaml
|
|
# CRDs are pulled from the bind-operator repo at the matching tag rather than
|
|
# vendored here, so they never drift from the operator.
|
|
- https://git.unkin.net/unkin/bind-operator/raw/tag/v0.3.1/config/crd/install.yaml
|
|
- rbac.yaml
|
|
- agent-dns-rbac.yaml
|
|
- deployment.yaml
|
|
- vpa.yaml
|