apply records before the apex NS, so in-zone glue exists first
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful

named rejects an apex NS pointing at an in-zone name with no address record,
so the glue has to land in an earlier transaction.
This commit is contained in:
2026-09-26 19:41:53 +10:00
parent 08d46ccce0
commit cc714dc2b4
4 changed files with 63 additions and 28 deletions
+6 -1
View File
@@ -169,6 +169,9 @@ func zoneNameservers(zone *bindv1alpha1.BindZone, cluster *bindv1alpha1.BindClus
// no NS records — a primary always has one. Nothing is retracted in that case:
// retracting blind is what turns a delete into "delete the last NS", which named
// rejects outright.
// ponytail: names already published are diffed by name only, so an edit to just
// the TTL never republishes them (dig +short cannot report a TTL). Re-add the
// whole desired set each pass if TTL edits need to converge.
func apexNSUpdates(zone *bindv1alpha1.BindZone, desired, live []string, ttl int32) []bind.RecordUpdate {
apex := fqdn("@", zone.Spec.ZoneName)
add := missing(desired, live)
@@ -177,8 +180,10 @@ func apexNSUpdates(zone *bindv1alpha1.BindZone, desired, live []string, ttl int3
if len(add) > 0 {
updates = append(updates, bind.RecordUpdate{FQDN: apex, Type: "NS", TTL: ttl, Values: add, PerValue: true})
}
// missing() yields nothing against an empty live set, so an unreadable RRset
// retracts nothing on its own.
del := missing(live, desired)
if len(live) == 0 || len(del) == 0 {
if len(del) == 0 {
return updates
}
updates = append(updates, bind.RecordUpdate{FQDN: apex, Type: "NS", Values: del, PerValue: true, Delete: true})