read the live apex NS with a signed query, retract nothing when unreadable
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful

An unsigned localhost query is REFUSED for a zone behind a key-matched view and
answers empty with exit 0; signing it with the update creds reaches the view.
This commit is contained in:
2026-09-26 19:25:06 +10:00
parent dc57ac1b2d
commit 08d46ccce0
9 changed files with 67 additions and 65 deletions
@@ -100,8 +100,10 @@ spec:
sync on every reconcile. Each entry is a full domain name, never relative
to the zone. Prefer out-of-zone names glued by the parent: an
in-zone name needs an address record in the zone, and the seed can only
supply the primary pod's (unstable) IP for it. When empty the apex NS is
the primary's stable in-cluster DNS name.
supply the primary pod's (unstable) IP for it. When empty the operator
leaves the apex NS alone and a newly seeded zone gets the primary's stable
in-cluster DNS name; clearing the field later does not retract what it
published.
items:
type: string
type: array
@@ -243,13 +245,6 @@ spec:
x-kubernetes-list-map-keys:
- type
x-kubernetes-list-type: map
nameservers:
description: |-
Nameservers records the apex NS names the operator last published, so a
change to spec.nameservers knows which entries to retract.
items:
type: string
type: array
observedGeneration:
format: int64
type: integer
+4 -9
View File
@@ -2766,8 +2766,10 @@ spec:
sync on every reconcile. Each entry is a full domain name, never relative
to the zone. Prefer out-of-zone names glued by the parent: an
in-zone name needs an address record in the zone, and the seed can only
supply the primary pod's (unstable) IP for it. When empty the apex NS is
the primary's stable in-cluster DNS name.
supply the primary pod's (unstable) IP for it. When empty the operator
leaves the apex NS alone and a newly seeded zone gets the primary's stable
in-cluster DNS name; clearing the field later does not retract what it
published.
items:
type: string
type: array
@@ -2909,13 +2911,6 @@ spec:
x-kubernetes-list-map-keys:
- type
x-kubernetes-list-type: map
nameservers:
description: |-
Nameservers records the apex NS names the operator last published, so a
change to spec.nameservers knows which entries to retract.
items:
type: string
type: array
observedGeneration:
format: int64
type: integer