reject an apex NS DNSRecord instead of appending to the live RRset
BIND ignores an RRset-wide delete at a zone apex, so a DNSRecord for the apex NS can only add to what the zone was seeded with while reporting success. BindZone.spec.nameservers converges it per rdata.
This commit is contained in:
@@ -44,6 +44,8 @@ func (r *DNSRecordReconciler) Reconcile(ctx context.Context, req ctrl.Request) (
|
||||
}
|
||||
primaryPod := primaryPodName(cluster.Name)
|
||||
name := fqdn(record.Spec.Name, zone.Spec.ZoneName)
|
||||
// CEL on the spec catches "@" and ""; a zone-qualified apex name reaches here.
|
||||
apexNS := isApexNS(record.Spec.Name, record.Spec.Type, zone.Spec.ZoneName)
|
||||
|
||||
creds, err := resolveTSIG(ctx, r.Client, record.Namespace, zone.Spec.UpdateKeyRef)
|
||||
if err != nil {
|
||||
@@ -53,7 +55,7 @@ func (r *DNSRecordReconciler) Reconcile(ctx context.Context, req ctrl.Request) (
|
||||
// Deletion via finalizer: remove the RRset.
|
||||
if !record.DeletionTimestamp.IsZero() {
|
||||
if controllerutil.ContainsFinalizer(&record, finalizer) {
|
||||
if primaryReady(ctx, r.Client, cluster) && r.Exec != nil {
|
||||
if primaryReady(ctx, r.Client, cluster) && r.Exec != nil && !apexNS {
|
||||
_ = r.Exec.NSUpdate(ctx, record.Namespace, primaryPod, zone.Spec.ZoneName, creds,
|
||||
[]bind.RecordUpdate{{FQDN: name, Type: record.Spec.Type, Delete: true}})
|
||||
}
|
||||
@@ -65,6 +67,11 @@ func (r *DNSRecordReconciler) Reconcile(ctx context.Context, req ctrl.Request) (
|
||||
return ctrl.Result{}, nil
|
||||
}
|
||||
|
||||
if apexNS {
|
||||
return r.setPhase(ctx, &record, "Error", "ApexNSUnsupported",
|
||||
"BIND ignores an RRset-wide delete at a zone apex, so this record can only append; publish the apex NS via BindZone.spec.nameservers")
|
||||
}
|
||||
|
||||
if !controllerutil.ContainsFinalizer(&record, finalizer) {
|
||||
controllerutil.AddFinalizer(&record, finalizer)
|
||||
if err := r.Update(ctx, &record); err != nil {
|
||||
|
||||
Reference in New Issue
Block a user