apply records before the apex NS, so in-zone glue exists first
named rejects an apex NS pointing at an in-zone name with no address record, so the glue has to land in an earlier transaction.
This commit is contained in:
@@ -118,17 +118,27 @@ func (r *BindZoneReconciler) Reconcile(ctx context.Context, req ctrl.Request) (c
|
||||
return r.setPhase(ctx, &zone, "Error", "AddZoneFailed", err.Error())
|
||||
}
|
||||
|
||||
// Converge the apex NS on every pass, not only at seed time, so a zone that
|
||||
// was seeded with the placeholder moves onto its real nameservers. Only for a
|
||||
// zone that declared them: otherwise the operator would fight whoever else
|
||||
// manages the RRset.
|
||||
// Records are applied before the apex NS: an in-zone nameserver's address
|
||||
// record has to exist first, or named rejects the apex transaction with a
|
||||
// post-update nameserver sanity check failure.
|
||||
recordCount := 0
|
||||
if isPrimaryType(zone.Spec.Type) {
|
||||
creds, credErr := r.zoneUpdateCreds(ctx, &zone)
|
||||
if nsDeclared {
|
||||
if credErr != nil {
|
||||
return r.setPhase(ctx, &zone, "Error", "NoUpdateKey", credErr.Error())
|
||||
records := recordsToUpdates(zone.Spec.ZoneName, zone.Spec.Records, zone.Spec.DefaultTTL)
|
||||
if isPrimaryType(zone.Spec.Type) && (len(records) > 0 || nsDeclared) {
|
||||
creds, err := r.zoneUpdateCreds(ctx, &zone)
|
||||
if err != nil {
|
||||
return r.setPhase(ctx, &zone, "Error", "NoUpdateKey", err.Error())
|
||||
}
|
||||
if len(records) > 0 {
|
||||
if err := r.Exec.NSUpdate(ctx, zone.Namespace, primaryPod, zone.Spec.ZoneName, creds, records); err != nil {
|
||||
return r.setPhase(ctx, &zone, "Error", "RecordUpdateFailed", err.Error())
|
||||
}
|
||||
recordCount = len(records)
|
||||
}
|
||||
// Converge the apex NS on every pass, not only at seed time, so a zone
|
||||
// seeded with the placeholder moves onto its real nameservers. Only for a
|
||||
// zone that declared them: otherwise the operator would fight whoever else
|
||||
// manages the RRset.
|
||||
if nsDeclared {
|
||||
live, err := r.Exec.ApexNS(ctx, zone.Namespace, primaryPod, zone.Spec.ZoneName, creds)
|
||||
if err != nil {
|
||||
return r.setPhase(ctx, &zone, "Error", "ApexNSQueryFailed", err.Error())
|
||||
@@ -138,21 +148,12 @@ func (r *BindZoneReconciler) Reconcile(ctx context.Context, req ctrl.Request) (c
|
||||
}
|
||||
if apex := apexNSUpdates(&zone, nameservers, live, nsTTL); len(apex) > 0 {
|
||||
if err := r.Exec.NSUpdate(ctx, zone.Namespace, primaryPod, zone.Spec.ZoneName, creds, apex); err != nil {
|
||||
return r.setPhase(ctx, &zone, "Error", "ApexNSSyncFailed", err.Error())
|
||||
return r.setPhase(ctx, &zone, "Error", "ApexNSSyncFailed",
|
||||
fmt.Sprintf("%s (a nameserver inside the zone needs an address record here)", err))
|
||||
}
|
||||
logger.Info("apex NS converged", "zone", zone.Spec.ZoneName, "nameservers", nameservers)
|
||||
}
|
||||
}
|
||||
// Seed static records.
|
||||
if updates := recordsToUpdates(zone.Spec.ZoneName, zone.Spec.Records, zone.Spec.DefaultTTL); len(updates) > 0 {
|
||||
if credErr != nil {
|
||||
return r.setPhase(ctx, &zone, "Error", "NoUpdateKey", credErr.Error())
|
||||
}
|
||||
if err := r.Exec.NSUpdate(ctx, zone.Namespace, primaryPod, zone.Spec.ZoneName, creds, updates); err != nil {
|
||||
return r.setPhase(ctx, &zone, "Error", "RecordUpdateFailed", err.Error())
|
||||
}
|
||||
recordCount = len(updates)
|
||||
}
|
||||
}
|
||||
|
||||
// Register in the catalog so secondaries auto-provision.
|
||||
|
||||
Reference in New Issue
Block a user