reject an apex NS DNSRecord instead of appending to the live RRset
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful

BIND ignores an RRset-wide delete at a zone apex, so a DNSRecord for the
apex NS can only add to what the zone was seeded with while reporting
success. BindZone.spec.nameservers converges it per rdata.
This commit is contained in:
2026-09-27 10:58:45 +10:00
parent 057575b9b5
commit afb4fe2631
6 changed files with 56 additions and 3 deletions
+9 -2
View File
@@ -39,12 +39,19 @@ func fqdn(name, zone string) string {
return name + "." + zone
}
// isApexNS reports whether an owner/type pair addresses a zone's apex NS RRset.
// BIND ignores an RRset-wide delete there, so such a record can only append:
// the apex NS is converged per rdata from BindZone.spec.nameservers.
func isApexNS(name, typ, zone string) bool {
return strings.EqualFold(typ, "NS") && strings.EqualFold(fqdn(name, zone), fqdn("@", zone))
}
func recordsToUpdates(zone string, records []bindv1alpha1.Record, defaultTTL int32) []bind.RecordUpdate {
updates := make([]bind.RecordUpdate, 0, len(records))
for _, rec := range records {
// The apex NS RRset is converged by apexNSUpdates: an RRset-wide delete
// here is ignored by BIND and would only append to the live set.
if strings.EqualFold(rec.Type, "NS") && fqdn(rec.Name, zone) == fqdn("@", zone) {
if isApexNS(rec.Name, rec.Type, zone) {
continue
}
ttl := defaultTTL
@@ -140,7 +147,7 @@ func zoneNameservers(zone *bindv1alpha1.BindZone, cluster *bindv1alpha1.BindClus
if len(names) > 0 {
break
}
if !strings.EqualFold(rec.Type, "NS") || fqdn(rec.Name, zone.Spec.ZoneName) != fqdn("@", zone.Spec.ZoneName) {
if !isApexNS(rec.Name, rec.Type, zone.Spec.ZoneName) {
continue
}
for _, v := range rec.Values {