reconcile zone apex NS off the pod IP placeholder
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful

Add BindZone.spec.nameservers and sync the apex NS RRset on every reconcile.
This commit is contained in:
2026-09-26 18:27:11 +10:00
parent 03df5d56b4
commit 4a41cbc427
14 changed files with 346 additions and 39 deletions
@@ -94,6 +94,17 @@ spec:
items:
type: string
type: array
nameservers:
description: |-
Nameservers are the names published in the zone's apex NS RRset, kept in
sync on every reconcile. Each entry is a full domain name, never relative
to the zone. Prefer out-of-zone names glued by the parent: an
in-zone name needs an address record in the zone, and the seed can only
supply the primary pod's (unstable) IP for it. When empty the apex NS is
the primary's stable in-cluster DNS name.
items:
type: string
type: array
primaries:
description: Primaries lists source servers for a secondary/stub-type
zone.
+11
View File
@@ -2760,6 +2760,17 @@ spec:
items:
type: string
type: array
nameservers:
description: |-
Nameservers are the names published in the zone's apex NS RRset, kept in
sync on every reconcile. Each entry is a full domain name, never relative
to the zone. Prefer out-of-zone names glued by the parent: an
in-zone name needs an address record in the zone, and the seed can only
supply the primary pod's (unstable) IP for it. When empty the apex NS is
the primary's stable in-cluster DNS name.
items:
type: string
type: array
primaries:
description: Primaries lists source servers for a secondary/stub-type
zone.
+4 -3
View File
@@ -71,10 +71,11 @@ spec:
- key transfer-key
updateKeyRef: transfer-key
dynamicUpdate: true
# Published apex NS, kept in sync on every reconcile. Full names only; an
# in-zone name (as here) needs its address record below.
nameservers:
- ns1.internal.example.com.
records:
- name: "@"
type: NS
values: ["ns1.internal.example.com."]
- name: ns1
type: A
values: ["10.0.0.53"]