Restrict zone names to DNS label characters
This commit is contained in:
@@ -11,7 +11,11 @@ type BindCatalogZoneSpec struct {
|
|||||||
// ClusterRef names the owning BindCluster.
|
// ClusterRef names the owning BindCluster.
|
||||||
ClusterRef string `json:"clusterRef"`
|
ClusterRef string `json:"clusterRef"`
|
||||||
|
|
||||||
// ZoneName is the catalog zone's own origin, e.g. "catalog.internal".
|
// ZoneName is the catalog zone's own origin, e.g. "catalog.internal". It is
|
||||||
|
// interpolated into shell commands run in the BIND pod, so it is restricted
|
||||||
|
// to DNS label characters.
|
||||||
|
// +kubebuilder:validation:Pattern=`^([A-Za-z0-9_]([A-Za-z0-9_-]*[A-Za-z0-9_])?\.)*[A-Za-z0-9_]([A-Za-z0-9_-]*[A-Za-z0-9_])?\.?$`
|
||||||
|
// +kubebuilder:validation:MaxLength=253
|
||||||
ZoneName string `json:"zoneName"`
|
ZoneName string `json:"zoneName"`
|
||||||
|
|
||||||
// DefaultPrimaries are the addresses member zones point at on secondaries.
|
// DefaultPrimaries are the addresses member zones point at on secondaries.
|
||||||
|
|||||||
@@ -58,7 +58,8 @@ type BindClusterSpec struct {
|
|||||||
// +optional
|
// +optional
|
||||||
Replicas int32 `json:"replicas,omitempty"`
|
Replicas int32 `json:"replicas,omitempty"`
|
||||||
|
|
||||||
// Image is the BIND9 container image. Must ship named, rndc and nsupdate.
|
// Image is the BIND9 container image. Must ship named, rndc, nsupdate and
|
||||||
|
// the POSIX tools the operator execs: sh, mkdir, dirname, head, od, tr, mv.
|
||||||
// +kubebuilder:default="internetsystemsconsortium/bind9:9.20"
|
// +kubebuilder:default="internetsystemsconsortium/bind9:9.20"
|
||||||
// +optional
|
// +optional
|
||||||
Image string `json:"image,omitempty"`
|
Image string `json:"image,omitempty"`
|
||||||
|
|||||||
@@ -42,7 +42,11 @@ type BindPolicySpec struct {
|
|||||||
// +optional
|
// +optional
|
||||||
ViewRef string `json:"viewRef,omitempty"`
|
ViewRef string `json:"viewRef,omitempty"`
|
||||||
|
|
||||||
// ZoneName is the RPZ zone origin, e.g. "rpz.internal".
|
// ZoneName is the RPZ zone origin, e.g. "rpz.internal". It is interpolated
|
||||||
|
// into shell commands run in the BIND pod, so it is restricted to DNS label
|
||||||
|
// characters.
|
||||||
|
// +kubebuilder:validation:Pattern=`^([A-Za-z0-9_]([A-Za-z0-9_-]*[A-Za-z0-9_])?\.)*[A-Za-z0-9_]([A-Za-z0-9_-]*[A-Za-z0-9_])?\.?$`
|
||||||
|
// +kubebuilder:validation:MaxLength=253
|
||||||
ZoneName string `json:"zoneName"`
|
ZoneName string `json:"zoneName"`
|
||||||
|
|
||||||
// Order controls this policy's position in the response-policy clause.
|
// Order controls this policy's position in the response-policy clause.
|
||||||
|
|||||||
@@ -48,6 +48,10 @@ type BindZoneSpec struct {
|
|||||||
ViewRef string `json:"viewRef,omitempty"`
|
ViewRef string `json:"viewRef,omitempty"`
|
||||||
|
|
||||||
// ZoneName is the DNS origin, e.g. "example.com" or "2.0.192.in-addr.arpa".
|
// ZoneName is the DNS origin, e.g. "example.com" or "2.0.192.in-addr.arpa".
|
||||||
|
// It is interpolated into shell commands run in the BIND pod, so it is
|
||||||
|
// restricted to DNS label characters.
|
||||||
|
// +kubebuilder:validation:Pattern=`^([A-Za-z0-9_]([A-Za-z0-9_-]*[A-Za-z0-9_])?\.)*[A-Za-z0-9_]([A-Za-z0-9_-]*[A-Za-z0-9_])?\.?$`
|
||||||
|
// +kubebuilder:validation:MaxLength=253
|
||||||
ZoneName string `json:"zoneName"`
|
ZoneName string `json:"zoneName"`
|
||||||
|
|
||||||
// Type is the zone type. Defaults to primary.
|
// Type is the zone type. Defaults to primary.
|
||||||
|
|||||||
@@ -73,7 +73,12 @@ spec:
|
|||||||
transfers to secondaries.
|
transfers to secondaries.
|
||||||
type: string
|
type: string
|
||||||
zoneName:
|
zoneName:
|
||||||
description: ZoneName is the catalog zone's own origin, e.g. "catalog.internal".
|
description: |-
|
||||||
|
ZoneName is the catalog zone's own origin, e.g. "catalog.internal". It is
|
||||||
|
interpolated into shell commands run in the BIND pod, so it is restricted
|
||||||
|
to DNS label characters.
|
||||||
|
maxLength: 253
|
||||||
|
pattern: ^([A-Za-z0-9_]([A-Za-z0-9_-]*[A-Za-z0-9_])?\.)*[A-Za-z0-9_]([A-Za-z0-9_-]*[A-Za-z0-9_])?\.?$
|
||||||
type: string
|
type: string
|
||||||
required:
|
required:
|
||||||
- clusterRef
|
- clusterRef
|
||||||
|
|||||||
@@ -995,8 +995,9 @@ spec:
|
|||||||
type: array
|
type: array
|
||||||
image:
|
image:
|
||||||
default: internetsystemsconsortium/bind9:9.20
|
default: internetsystemsconsortium/bind9:9.20
|
||||||
description: Image is the BIND9 container image. Must ship named,
|
description: |-
|
||||||
rndc and nsupdate.
|
Image is the BIND9 container image. Must ship named, rndc, nsupdate and
|
||||||
|
the POSIX tools the operator execs: sh, mkdir, dirname, head, od, tr, mv.
|
||||||
type: string
|
type: string
|
||||||
imagePullPolicy:
|
imagePullPolicy:
|
||||||
description: ImagePullPolicy for the BIND container.
|
description: ImagePullPolicy for the BIND container.
|
||||||
|
|||||||
@@ -118,7 +118,12 @@ spec:
|
|||||||
description: ViewRef optionally scopes the policy to a single view.
|
description: ViewRef optionally scopes the policy to a single view.
|
||||||
type: string
|
type: string
|
||||||
zoneName:
|
zoneName:
|
||||||
description: ZoneName is the RPZ zone origin, e.g. "rpz.internal".
|
description: |-
|
||||||
|
ZoneName is the RPZ zone origin, e.g. "rpz.internal". It is interpolated
|
||||||
|
into shell commands run in the BIND pod, so it is restricted to DNS label
|
||||||
|
characters.
|
||||||
|
maxLength: 253
|
||||||
|
pattern: ^([A-Za-z0-9_]([A-Za-z0-9_-]*[A-Za-z0-9_])?\.)*[A-Za-z0-9_]([A-Za-z0-9_-]*[A-Za-z0-9_])?\.?$
|
||||||
type: string
|
type: string
|
||||||
required:
|
required:
|
||||||
- clusterRef
|
- clusterRef
|
||||||
|
|||||||
@@ -159,7 +159,12 @@ spec:
|
|||||||
description: ViewRef optionally binds this zone to a BindView.
|
description: ViewRef optionally binds this zone to a BindView.
|
||||||
type: string
|
type: string
|
||||||
zoneName:
|
zoneName:
|
||||||
description: ZoneName is the DNS origin, e.g. "example.com" or "2.0.192.in-addr.arpa".
|
description: |-
|
||||||
|
ZoneName is the DNS origin, e.g. "example.com" or "2.0.192.in-addr.arpa".
|
||||||
|
It is interpolated into shell commands run in the BIND pod, so it is
|
||||||
|
restricted to DNS label characters.
|
||||||
|
maxLength: 253
|
||||||
|
pattern: ^([A-Za-z0-9_]([A-Za-z0-9_-]*[A-Za-z0-9_])?\.)*[A-Za-z0-9_]([A-Za-z0-9_-]*[A-Za-z0-9_])?\.?$
|
||||||
type: string
|
type: string
|
||||||
required:
|
required:
|
||||||
- clusterRef
|
- clusterRef
|
||||||
|
|||||||
+21
-5
@@ -219,7 +219,12 @@ spec:
|
|||||||
transfers to secondaries.
|
transfers to secondaries.
|
||||||
type: string
|
type: string
|
||||||
zoneName:
|
zoneName:
|
||||||
description: ZoneName is the catalog zone's own origin, e.g. "catalog.internal".
|
description: |-
|
||||||
|
ZoneName is the catalog zone's own origin, e.g. "catalog.internal". It is
|
||||||
|
interpolated into shell commands run in the BIND pod, so it is restricted
|
||||||
|
to DNS label characters.
|
||||||
|
maxLength: 253
|
||||||
|
pattern: ^([A-Za-z0-9_]([A-Za-z0-9_-]*[A-Za-z0-9_])?\.)*[A-Za-z0-9_]([A-Za-z0-9_-]*[A-Za-z0-9_])?\.?$
|
||||||
type: string
|
type: string
|
||||||
required:
|
required:
|
||||||
- clusterRef
|
- clusterRef
|
||||||
@@ -1300,8 +1305,9 @@ spec:
|
|||||||
type: array
|
type: array
|
||||||
image:
|
image:
|
||||||
default: internetsystemsconsortium/bind9:9.20
|
default: internetsystemsconsortium/bind9:9.20
|
||||||
description: Image is the BIND9 container image. Must ship named,
|
description: |-
|
||||||
rndc and nsupdate.
|
Image is the BIND9 container image. Must ship named, rndc, nsupdate and
|
||||||
|
the POSIX tools the operator execs: sh, mkdir, dirname, head, od, tr, mv.
|
||||||
type: string
|
type: string
|
||||||
imagePullPolicy:
|
imagePullPolicy:
|
||||||
description: ImagePullPolicy for the BIND container.
|
description: ImagePullPolicy for the BIND container.
|
||||||
@@ -1937,7 +1943,12 @@ spec:
|
|||||||
description: ViewRef optionally scopes the policy to a single view.
|
description: ViewRef optionally scopes the policy to a single view.
|
||||||
type: string
|
type: string
|
||||||
zoneName:
|
zoneName:
|
||||||
description: ZoneName is the RPZ zone origin, e.g. "rpz.internal".
|
description: |-
|
||||||
|
ZoneName is the RPZ zone origin, e.g. "rpz.internal". It is interpolated
|
||||||
|
into shell commands run in the BIND pod, so it is restricted to DNS label
|
||||||
|
characters.
|
||||||
|
maxLength: 253
|
||||||
|
pattern: ^([A-Za-z0-9_]([A-Za-z0-9_-]*[A-Za-z0-9_])?\.)*[A-Za-z0-9_]([A-Za-z0-9_-]*[A-Za-z0-9_])?\.?$
|
||||||
type: string
|
type: string
|
||||||
required:
|
required:
|
||||||
- clusterRef
|
- clusterRef
|
||||||
@@ -2813,7 +2824,12 @@ spec:
|
|||||||
description: ViewRef optionally binds this zone to a BindView.
|
description: ViewRef optionally binds this zone to a BindView.
|
||||||
type: string
|
type: string
|
||||||
zoneName:
|
zoneName:
|
||||||
description: ZoneName is the DNS origin, e.g. "example.com" or "2.0.192.in-addr.arpa".
|
description: |-
|
||||||
|
ZoneName is the DNS origin, e.g. "example.com" or "2.0.192.in-addr.arpa".
|
||||||
|
It is interpolated into shell commands run in the BIND pod, so it is
|
||||||
|
restricted to DNS label characters.
|
||||||
|
maxLength: 253
|
||||||
|
pattern: ^([A-Za-z0-9_]([A-Za-z0-9_-]*[A-Za-z0-9_])?\.)*[A-Za-z0-9_]([A-Za-z0-9_-]*[A-Za-z0-9_])?\.?$
|
||||||
type: string
|
type: string
|
||||||
required:
|
required:
|
||||||
- clusterRef
|
- clusterRef
|
||||||
|
|||||||
Reference in New Issue
Block a user