Target upstream ISC bind9 image
Uses internetsystemsconsortium/bind9 as the default base image instead of a self-hosted one, verified against internetsystemsconsortium/bind9:9.20 (runs as root; named/rndc/nsupdate at /usr/sbin,/usr/sbin,/usr/bin). - project operator config at /etc/bind-operator instead of overmounting the image's /etc/bind (keeps bind.keys / base config intact) - reference named/rndc/nsupdate by absolute path (exec PATH may exclude /usr/sbin) - centralise filesystem + binary paths in internal/bind/consts.go - default spec.image to internetsystemsconsortium/bind9:9.20
This commit is contained in:
@@ -109,7 +109,7 @@ func (r *BindClusterReconciler) reconcileRNDCSecret(ctx context.Context, c *bind
|
||||
return genErr
|
||||
}
|
||||
keyClause := bind.KeyClause("rndc-key", "hmac-sha256", secret)
|
||||
rndcConf := fmt.Sprintf("include \"/etc/bind/rndc.key\";\noptions {\n default-key \"rndc-key\";\n default-server 127.0.0.1;\n default-port 953;\n};\n")
|
||||
rndcConf := fmt.Sprintf("include \"%s\";\noptions {\n default-key \"rndc-key\";\n default-server 127.0.0.1;\n default-port 953;\n};\n", bind.RndcKeyPath)
|
||||
s := &corev1.Secret{
|
||||
ObjectMeta: metav1.ObjectMeta{Name: name, Namespace: c.Namespace, Labels: commonLabels(c.Name)},
|
||||
Data: map[string][]byte{
|
||||
@@ -259,7 +259,7 @@ func (r *BindClusterReconciler) reconcileStatefulSet(ctx context.Context, c *bin
|
||||
replicas := c.Spec.Replicas
|
||||
image := c.Spec.Image
|
||||
if image == "" {
|
||||
image = "git.unkin.net/unkin/bind9:latest"
|
||||
image = defaultBindImage
|
||||
}
|
||||
storageSize := c.Spec.StorageSize
|
||||
if storageSize == "" {
|
||||
@@ -295,15 +295,15 @@ func (r *BindClusterReconciler) reconcileStatefulSet(ctx context.Context, c *bin
|
||||
Name: bind.ContainerName,
|
||||
Image: image,
|
||||
ImagePullPolicy: c.Spec.ImagePullPolicy,
|
||||
Command: []string{"/bin/sh", "/etc/bind/entrypoint.sh"},
|
||||
Command: []string{"/bin/sh", bind.EntrypointPath},
|
||||
Ports: []corev1.ContainerPort{
|
||||
{Name: "dns-udp", ContainerPort: 53, Protocol: corev1.ProtocolUDP},
|
||||
{Name: "dns-tcp", ContainerPort: 53, Protocol: corev1.ProtocolTCP},
|
||||
},
|
||||
Resources: c.Spec.Resources,
|
||||
VolumeMounts: []corev1.VolumeMount{
|
||||
{Name: "bind-etc", MountPath: "/etc/bind", ReadOnly: true},
|
||||
{Name: "run", MountPath: "/run/named"},
|
||||
{Name: "bind-etc", MountPath: bind.ConfigDir, ReadOnly: true},
|
||||
{Name: "run", MountPath: bind.RunDir},
|
||||
{Name: "data", MountPath: bind.DataDir},
|
||||
},
|
||||
ReadinessProbe: &corev1.Probe{
|
||||
|
||||
@@ -23,6 +23,9 @@ const (
|
||||
clusterLabel = "bind.unkin.net/cluster"
|
||||
|
||||
finalizer = "bind.unkin.net/finalizer"
|
||||
|
||||
// defaultBindImage is used when BindCluster.spec.image is empty.
|
||||
defaultBindImage = "internetsystemsconsortium/bind9:9.20"
|
||||
)
|
||||
|
||||
func headlessServiceName(cluster string) string { return cluster + "-headless" }
|
||||
|
||||
@@ -2,6 +2,7 @@ package controller
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
|
||||
corev1 "k8s.io/api/core/v1"
|
||||
apierrors "k8s.io/apimachinery/pkg/api/errors"
|
||||
@@ -10,6 +11,7 @@ import (
|
||||
ctrl "sigs.k8s.io/controller-runtime"
|
||||
|
||||
bindv1alpha1 "git.unkin.net/unkin/bind-operator/api/v1alpha1"
|
||||
"git.unkin.net/unkin/bind-operator/internal/bind"
|
||||
)
|
||||
|
||||
func intstrFromInt(i int) intstr.IntOrString { return intstr.FromInt(i) }
|
||||
@@ -26,17 +28,17 @@ func podReady(pod *corev1.Pod) bool {
|
||||
// entrypointScript selects the primary or secondary named.conf based on the
|
||||
// pod's StatefulSet ordinal and launches named in the foreground.
|
||||
func entrypointScript() string {
|
||||
return `#!/bin/sh
|
||||
return fmt.Sprintf(`#!/bin/sh
|
||||
set -eu
|
||||
ORD="${HOSTNAME##*-}"
|
||||
if [ "$ORD" = "0" ]; then
|
||||
cp /etc/bind/named.conf.primary /run/named/named.conf
|
||||
cp %[1]s %[3]s
|
||||
else
|
||||
cp /etc/bind/named.conf.secondary /run/named/named.conf
|
||||
cp %[2]s %[3]s
|
||||
fi
|
||||
mkdir -p /var/lib/named/zones /var/lib/named/catalog
|
||||
exec named -g -c /run/named/named.conf
|
||||
`
|
||||
mkdir -p %[4]s/zones %[4]s/catalog
|
||||
exec %[5]s -g -c %[3]s
|
||||
`, bind.NamedConfPrimary, bind.NamedConfSecondary, bind.NamedConfRun, bind.DataDir, bind.NamedBin)
|
||||
}
|
||||
|
||||
func (r *BindClusterReconciler) upsertService(ctx context.Context, c *bindv1alpha1.BindCluster, desired *corev1.Service) error {
|
||||
|
||||
Reference in New Issue
Block a user