Render forward zones into named.conf on every pod
type:forward zones are pure configuration (conditional forwarding), not replicated data, so a resolver needs them on all pods. They were being rndc-addzone'd on the primary only, so queries hitting a secondary pod missed the forwarding. Render them into named.conf instead. - render forward zones inside their view (or top-level when no views) - BindCluster lists type:forward zones and watches BindZone to re-render - BindZone controller skips forward zones (config-managed, no addzone) - unit test for forward-zone-in-view rendering
This commit is contained in:
@@ -16,6 +16,10 @@ type RenderInput struct {
|
||||
Policies []bindv1alpha1.BindPolicy
|
||||
DNSSECPolicies []bindv1alpha1.BindDNSSECPolicy
|
||||
Catalog *bindv1alpha1.BindCatalogZone
|
||||
// Forwards are type:forward BindZones. They are pure configuration (no
|
||||
// replicated data), so they are rendered into named.conf on every pod
|
||||
// rather than added dynamically to the primary.
|
||||
Forwards []bindv1alpha1.BindZone
|
||||
// PrimaryAddress is the in-cluster address secondaries transfer from.
|
||||
PrimaryAddress string
|
||||
}
|
||||
@@ -90,6 +94,29 @@ func render(in RenderInput, isPrimary bool) string {
|
||||
b.WriteString(renderCatalogZoneDecl(in, isPrimary, ""))
|
||||
}
|
||||
|
||||
// Top-level forward zones (BIND only allows top-level zones when no views
|
||||
// are defined; in-view forward zones are rendered inside renderView).
|
||||
if len(in.Views) == 0 {
|
||||
for _, z := range in.Forwards {
|
||||
if z.Spec.ViewRef == "" {
|
||||
b.WriteString(renderForwardZone(z, ""))
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
return b.String()
|
||||
}
|
||||
|
||||
// renderForwardZone renders a type:forward zone clause.
|
||||
func renderForwardZone(z bindv1alpha1.BindZone, indent string) string {
|
||||
var b strings.Builder
|
||||
b.WriteString(fmt.Sprintf("%szone \"%s\" {\n", indent, z.Spec.ZoneName))
|
||||
b.WriteString(indent + " type forward;\n")
|
||||
b.WriteString(indent + " forward only;\n")
|
||||
if len(z.Spec.Forwarders) > 0 {
|
||||
b.WriteString(fmt.Sprintf("%s forwarders { %s };\n", indent, terminate(z.Spec.Forwarders)))
|
||||
}
|
||||
b.WriteString(indent + "};\n")
|
||||
return b.String()
|
||||
}
|
||||
|
||||
@@ -122,6 +149,12 @@ func renderView(v bindv1alpha1.BindView, in RenderInput, isPrimary bool) string
|
||||
if in.Catalog != nil {
|
||||
b.WriteString(renderCatalogZoneDecl(in, isPrimary, " "))
|
||||
}
|
||||
// Forward zones bound to this view.
|
||||
for _, z := range in.Forwards {
|
||||
if z.Spec.ViewRef == v.Name {
|
||||
b.WriteString(renderForwardZone(z, " "))
|
||||
}
|
||||
}
|
||||
b.WriteString("};\n\n")
|
||||
return b.String()
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user