read the live apex NS with a signed query, retract nothing when unreadable
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful

An unsigned localhost query is REFUSED for a zone behind a key-matched view and
answers empty with exit 0; signing it with the update creds reaches the view.
This commit is contained in:
2026-09-26 19:25:06 +10:00
parent dc57ac1b2d
commit 08d46ccce0
9 changed files with 67 additions and 65 deletions
+4 -6
View File
@@ -68,8 +68,10 @@ type BindZoneSpec struct {
// sync on every reconcile. Each entry is a full domain name, never relative
// to the zone. Prefer out-of-zone names glued by the parent: an
// in-zone name needs an address record in the zone, and the seed can only
// supply the primary pod's (unstable) IP for it. When empty the apex NS is
// the primary's stable in-cluster DNS name.
// supply the primary pod's (unstable) IP for it. When empty the operator
// leaves the apex NS alone and a newly seeded zone gets the primary's stable
// in-cluster DNS name; clearing the field later does not retract what it
// published.
// +optional
Nameservers []string `json:"nameservers,omitempty"`
@@ -126,10 +128,6 @@ type BindZoneStatus struct {
// RecordCount is the number of managed record sets applied.
// +optional
RecordCount int32 `json:"recordCount,omitempty"`
// Nameservers records the apex NS names the operator last published, so a
// change to spec.nameservers knows which entries to retract.
// +optional
Nameservers []string `json:"nameservers,omitempty"`
// Signed reports whether DNSSEC signing is active.
// +optional
Signed bool `json:"signed,omitempty"`
-5
View File
@@ -1017,11 +1017,6 @@ func (in *BindZoneSpec) DeepCopy() *BindZoneSpec {
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (in *BindZoneStatus) DeepCopyInto(out *BindZoneStatus) {
*out = *in
if in.Nameservers != nil {
in, out := &in.Nameservers, &out.Nameservers
*out = make([]string, len(*in))
copy(*out, *in)
}
if in.Conditions != nil {
in, out := &in.Conditions, &out.Conditions
*out = make([]v1.Condition, len(*in))