Files
argocd-apps/apps/base/bind-external/zones.yaml
T
Ben Vincent d6969ca390
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful
Add bind-external namespace for externally-reachable zones
We self-delegate _acme-challenge.unkin.net into an acme.unkin.net zone we serve,
so cert-manager can solve Let's Encrypt DNS-01 over RFC2136/TSIG. That needs a
publicly-reachable authoritative BIND, separate from the internal estate.

- Add app bind-external (base + au-syd1 overlay) and register it in the platform
  ApplicationSet and AppProject destinations.
- Add BindCluster bind-external: authoritative-only, recursion off, no
  forwarding, transfers denied except the keyed catalog/zone AXFR; 2 replicas;
  primaryService is a dmz-pinned PureLB LoadBalancer (198.18.199.53).
- Add BindZone acme.unkin.net (primary, dynamicUpdate) and BindTSIGKey
  certmanager (hmac-sha256), whose Secret reflects into the cert-manager
  namespace for the rfc2136 solver.

Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
2026-08-02 17:27:27 +10:00

20 lines
591 B
YAML

---
# Self-delegated ACME challenge zone. Google Cloud DNS holds a one-time
# _acme-challenge.unkin.net CNAME -> _acme-challenge.acme.unkin.net and an
# acme.unkin.net NS delegation pointing here; cert-manager writes the challenge
# TXT records via RFC2136 authenticated with the certmanager key.
apiVersion: bind.unkin.net/v1alpha1
kind: BindZone
metadata:
name: acme-unkin-net
namespace: bind-external
spec:
clusterRef: bind-external
zoneName: acme.unkin.net
type: primary
defaultTTL: 60
dynamicUpdate: true
updateKeyRef: certmanager
allowTransfer:
- key certmanager