reject an apex NS DNSRecord instead of appending to the live RRset
BIND ignores an RRset-wide delete at a zone apex, so a DNSRecord for the apex NS can only add to what the zone was seeded with while reporting success. BindZone.spec.nameservers converges it per rdata.
This commit is contained in:
@@ -39,12 +39,19 @@ func fqdn(name, zone string) string {
|
||||
return name + "." + zone
|
||||
}
|
||||
|
||||
// isApexNS reports whether an owner/type pair addresses a zone's apex NS RRset.
|
||||
// BIND ignores an RRset-wide delete there, so such a record can only append:
|
||||
// the apex NS is converged per rdata from BindZone.spec.nameservers.
|
||||
func isApexNS(name, typ, zone string) bool {
|
||||
return strings.EqualFold(typ, "NS") && strings.EqualFold(fqdn(name, zone), fqdn("@", zone))
|
||||
}
|
||||
|
||||
func recordsToUpdates(zone string, records []bindv1alpha1.Record, defaultTTL int32) []bind.RecordUpdate {
|
||||
updates := make([]bind.RecordUpdate, 0, len(records))
|
||||
for _, rec := range records {
|
||||
// The apex NS RRset is converged by apexNSUpdates: an RRset-wide delete
|
||||
// here is ignored by BIND and would only append to the live set.
|
||||
if strings.EqualFold(rec.Type, "NS") && fqdn(rec.Name, zone) == fqdn("@", zone) {
|
||||
if isApexNS(rec.Name, rec.Type, zone) {
|
||||
continue
|
||||
}
|
||||
ttl := defaultTTL
|
||||
@@ -140,7 +147,7 @@ func zoneNameservers(zone *bindv1alpha1.BindZone, cluster *bindv1alpha1.BindClus
|
||||
if len(names) > 0 {
|
||||
break
|
||||
}
|
||||
if !strings.EqualFold(rec.Type, "NS") || fqdn(rec.Name, zone.Spec.ZoneName) != fqdn("@", zone.Spec.ZoneName) {
|
||||
if !isApexNS(rec.Name, rec.Type, zone.Spec.ZoneName) {
|
||||
continue
|
||||
}
|
||||
for _, v := range rec.Values {
|
||||
|
||||
Reference in New Issue
Block a user