216b1d72ac
records.yaml had grown to ten DNSRecord documents across two zones, so finding or reviewing a single record meant scanning the whole file and every change touched it. - move each record to authoritative/<zone>/<type>/<record>.yaml - add a kustomization.yaml per zone and per type directory - keep the git.unkin.net cutover record commented out, alongside a commented kustomization entry - move the DNSRecord-namespace rationale onto the authoritative kustomization - delete records.yaml Rendered output is unchanged. Reviewed-on: #501 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
28 lines
1.2 KiB
YAML
28 lines
1.2 KiB
YAML
---
|
|
# PRODUCTION CUTOVER RECORD — intentionally commented out.
|
|
# git.unkin.net currently resolves to the LIVE VM forge (HAProxy VRRP VIP
|
|
# 198.18.19.17), which holds every repo the estate depends on. Uncommenting this
|
|
# repoints the whole org's git.unkin.net at the new k8s Gitea gateway VIP, so it
|
|
# is the FINAL step of the forge migration — gated on the data migration (gitea
|
|
# dump/restore + SECRET_KEY copy) in argocd-apps docs/gitea-migration.md.
|
|
# NOTE: the live git.unkin.net answer is served by the puppet DNS master today
|
|
# (profiles::dns::master, records from PuppetDB); this k8s apex zone holds only
|
|
# SOA+NS + a few DNSRecords so far. Confirm the k8s bind cluster is the live
|
|
# authority for unkin.net (or update the puppet record instead) before relying
|
|
# on this CR at cutover.
|
|
# Uncomment this record AND its entry in kustomization.yaml to activate it.
|
|
# ---
|
|
# apiVersion: bind.unkin.net/v1alpha1
|
|
# kind: DNSRecord
|
|
# metadata:
|
|
# name: git-dns-internal
|
|
# namespace: bind-internal
|
|
# spec:
|
|
# zoneRef: unkin-net
|
|
# name: git
|
|
# type: A
|
|
# ttl: 600
|
|
# values:
|
|
# # traefik-internal gateway VIP; the gitea Gateway serves git.unkin.net there.
|
|
# - 198.18.200.4
|