Target upstream ISC bind9 image

Uses internetsystemsconsortium/bind9 as the default base image instead of
a self-hosted one, verified against internetsystemsconsortium/bind9:9.20
(runs as root; named/rndc/nsupdate at /usr/sbin,/usr/sbin,/usr/bin).

- project operator config at /etc/bind-operator instead of overmounting
  the image's /etc/bind (keeps bind.keys / base config intact)
- reference named/rndc/nsupdate by absolute path (exec PATH may exclude
  /usr/sbin)
- centralise filesystem + binary paths in internal/bind/consts.go
- default spec.image to internetsystemsconsortium/bind9:9.20
This commit is contained in:
2026-07-03 17:41:13 +10:00
parent fe5fbdaf6d
commit 4092a25f4f
11 changed files with 66 additions and 29 deletions
+2 -4
View File
@@ -20,9 +20,6 @@ type RenderInput struct {
PrimaryAddress string
}
// DataDir is where BIND keeps zone databases and journals (backed by the PVC).
const DataDir = "/var/lib/named"
// RenderNamedConf returns the primary and secondary named.conf contents for a
// cluster. Both variants are shipped in the ConfigMap; the entrypoint selects
// one based on the pod ordinal.
@@ -35,7 +32,8 @@ func render(in RenderInput, isPrimary bool) string {
var b strings.Builder
b.WriteString("// Managed by bind-operator. Do not edit.\n")
b.WriteString(`include "/etc/bind/keys/keys.conf";` + "\n\n")
b.WriteString(fmt.Sprintf("include \"%s\";\n", RndcKeyPath))
b.WriteString(fmt.Sprintf("include \"%s\";\n\n", KeysConfPath))
// Named ACLs (global scope).
acls := append([]bindv1alpha1.BindACL(nil), in.ACLs...)