apply records before the apex NS, so in-zone glue exists first
named rejects an apex NS pointing at an in-zone name with no address record, so the glue has to land in an earlier transaction.
This commit is contained in:
@@ -52,15 +52,22 @@ func (e *Executor) ApexNS(ctx context.Context, namespace, pod, zone string, cred
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("query apex NS of %s: %w (out: %s)", zone, err, out)
|
||||
}
|
||||
var ns []string
|
||||
return parseDigNames(out), nil
|
||||
}
|
||||
|
||||
// parseDigNames picks the answers out of `dig +short` output: one fully-qualified
|
||||
// name per line. Anything without a trailing dot is not a name, and dig prefixes
|
||||
// its diagnostics (a missing or mismatched TSIG key among them) with ';'.
|
||||
func parseDigNames(out string) []string {
|
||||
var names []string
|
||||
for _, line := range strings.Split(out, "\n") {
|
||||
// dig +short prints one fully-qualified name per line; anything without a
|
||||
// trailing dot is not an answer.
|
||||
if line = strings.TrimSpace(line); strings.HasSuffix(line, ".") {
|
||||
ns = append(ns, line)
|
||||
line = strings.TrimSpace(line)
|
||||
if strings.HasPrefix(line, ";") || !strings.HasSuffix(line, ".") {
|
||||
continue
|
||||
}
|
||||
names = append(names, line)
|
||||
}
|
||||
return ns, nil
|
||||
return names
|
||||
}
|
||||
|
||||
// nsupdateScript renders the nsupdate input for a set of changes.
|
||||
|
||||
Reference in New Issue
Block a user