reject an apex NS DNSRecord instead of appending to the live RRset
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful

BIND ignores an RRset-wide delete at a zone apex, so a DNSRecord for the
apex NS can only add to what the zone was seeded with while reporting
success. BindZone.spec.nameservers converges it per rdata.
This commit is contained in:
2026-09-27 10:58:45 +10:00
parent 057575b9b5
commit afb4fe2631
6 changed files with 56 additions and 3 deletions
+1
View File
@@ -6,6 +6,7 @@ import (
// DNSRecordSpec defines a single record set applied to a zone via TSIG dynamic
// update (nsupdate) — the external-dns write path expressed as a CRD.
// +kubebuilder:validation:XValidation:rule="!(self.type.lowerAscii() == 'ns' && (!has(self.name) || self.name == '@' || self.name.size() == 0))",message="an apex NS RRset cannot be managed by a DNSRecord: BIND ignores an RRset-wide delete at a zone apex, so this would only append. Use BindZone.spec.nameservers"
type DNSRecordSpec struct {
// ZoneRef names the BindZone this record belongs to. The cluster, view and
// update key are derived from the referenced zone.