reject an apex NS DNSRecord instead of appending to the live RRset
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful

BIND ignores an RRset-wide delete at a zone apex, so a DNSRecord for the
apex NS can only add to what the zone was seeded with while reporting
success. BindZone.spec.nameservers converges it per rdata.
This commit is contained in:
2026-09-27 10:58:45 +10:00
parent 057575b9b5
commit afb4fe2631
6 changed files with 56 additions and 3 deletions
@@ -86,6 +86,12 @@ spec:
- values
- zoneRef
type: object
x-kubernetes-validations:
- message: 'an apex NS RRset cannot be managed by a DNSRecord: BIND ignores
an RRset-wide delete at a zone apex, so this would only append. Use
BindZone.spec.nameservers'
rule: '!(self.type.lowerAscii() == ''ns'' && (!has(self.name) || self.name
== ''@'' || self.name.size() == 0))'
status:
description: DNSRecordStatus reports observed record state.
properties:
+6
View File
@@ -3022,6 +3022,12 @@ spec:
- values
- zoneRef
type: object
x-kubernetes-validations:
- message: 'an apex NS RRset cannot be managed by a DNSRecord: BIND ignores
an RRset-wide delete at a zone apex, so this would only append. Use
BindZone.spec.nameservers'
rule: '!(self.type.lowerAscii() == ''ns'' && (!has(self.name) || self.name
== ''@'' || self.name.size() == 0))'
status:
description: DNSRecordStatus reports observed record state.
properties: