read the live apex NS with a signed query, retract nothing when unreadable
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful

An unsigned localhost query is REFUSED for a zone behind a key-matched view and
answers empty with exit 0; signing it with the update creds reaches the view.
This commit is contained in:
2026-09-26 19:25:06 +10:00
parent dc57ac1b2d
commit 08d46ccce0
9 changed files with 67 additions and 65 deletions
+9 -13
View File
@@ -56,19 +56,15 @@ func TestZoneNameservers(t *testing.T) {
}
}
// Before the operator has recorded anything, the only names it can have published
// are the ones a seed writes; afterwards its record is the authority, so it never
// retracts a name someone else added.
func TestPublishedNameservers(t *testing.T) {
zone := zoneWith(bindv1alpha1.BindZoneSpec{})
want := "ns1.acme.unkin.net.," + stableNS
if got := publishedNameservers(zone, testCluster()); strings.Join(got, ",") != want {
t.Errorf("unrecorded: got %v; want %s", got, want)
}
zone.Status.Nameservers = []string{"a.ns.unkin.net."}
if got := publishedNameservers(zone, testCluster()); strings.Join(got, ",") != "a.ns.unkin.net." {
t.Errorf("recorded: got %v; want [a.ns.unkin.net.]", got)
}
// A query that cannot see the zone returns nothing, which must not be read as an
// empty apex: retracting blind means deleting the last NS record, which named
// rejects, leaving the zone stuck.
func TestApexNSUpdatesUnreadableLiveSetIsAdditive(t *testing.T) {
zone := zoneWith(bindv1alpha1.BindZoneSpec{Nameservers: []string{"ns1.unkin.net."}})
got := apexNSUpdates(zone, []string{"ns1.unkin.net."}, nil, 3600)
assertUpdates(t, got, []bind.RecordUpdate{
{FQDN: "acme.unkin.net.", Type: "NS", TTL: 3600, Values: []string{"ns1.unkin.net."}, PerValue: true},
})
}
// The apex NS RRset must be converged per record: an RRset-wide delete at the