read the live apex NS with a signed query, retract nothing when unreadable
An unsigned localhost query is REFUSED for a zone behind a key-matched view and answers empty with exit 0; signing it with the update creds reaches the view.
This commit is contained in:
@@ -100,8 +100,10 @@ spec:
|
||||
sync on every reconcile. Each entry is a full domain name, never relative
|
||||
to the zone. Prefer out-of-zone names glued by the parent: an
|
||||
in-zone name needs an address record in the zone, and the seed can only
|
||||
supply the primary pod's (unstable) IP for it. When empty the apex NS is
|
||||
the primary's stable in-cluster DNS name.
|
||||
supply the primary pod's (unstable) IP for it. When empty the operator
|
||||
leaves the apex NS alone and a newly seeded zone gets the primary's stable
|
||||
in-cluster DNS name; clearing the field later does not retract what it
|
||||
published.
|
||||
items:
|
||||
type: string
|
||||
type: array
|
||||
@@ -243,13 +245,6 @@ spec:
|
||||
x-kubernetes-list-map-keys:
|
||||
- type
|
||||
x-kubernetes-list-type: map
|
||||
nameservers:
|
||||
description: |-
|
||||
Nameservers records the apex NS names the operator last published, so a
|
||||
change to spec.nameservers knows which entries to retract.
|
||||
items:
|
||||
type: string
|
||||
type: array
|
||||
observedGeneration:
|
||||
format: int64
|
||||
type: integer
|
||||
|
||||
@@ -2766,8 +2766,10 @@ spec:
|
||||
sync on every reconcile. Each entry is a full domain name, never relative
|
||||
to the zone. Prefer out-of-zone names glued by the parent: an
|
||||
in-zone name needs an address record in the zone, and the seed can only
|
||||
supply the primary pod's (unstable) IP for it. When empty the apex NS is
|
||||
the primary's stable in-cluster DNS name.
|
||||
supply the primary pod's (unstable) IP for it. When empty the operator
|
||||
leaves the apex NS alone and a newly seeded zone gets the primary's stable
|
||||
in-cluster DNS name; clearing the field later does not retract what it
|
||||
published.
|
||||
items:
|
||||
type: string
|
||||
type: array
|
||||
@@ -2909,13 +2911,6 @@ spec:
|
||||
x-kubernetes-list-map-keys:
|
||||
- type
|
||||
x-kubernetes-list-type: map
|
||||
nameservers:
|
||||
description: |-
|
||||
Nameservers records the apex NS names the operator last published, so a
|
||||
change to spec.nameservers knows which entries to retract.
|
||||
items:
|
||||
type: string
|
||||
type: array
|
||||
observedGeneration:
|
||||
format: int64
|
||||
type: integer
|
||||
|
||||
Reference in New Issue
Block a user