retract apex NS from recorded state, not a live query
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful

An unsigned localhost query silently returns nothing for a zone behind a
BindView, which would strand the placeholder. Record what was published instead.
This commit is contained in:
2026-09-26 19:06:47 +10:00
parent e4ed6c8052
commit dc57ac1b2d
9 changed files with 134 additions and 76 deletions
-1
View File
@@ -23,7 +23,6 @@ const (
NamedBin = "/usr/sbin/named"
RndcBin = "/usr/sbin/rndc"
NsupdateBin = "/usr/bin/nsupdate"
DigBin = "/usr/bin/dig"
)
// Config file paths derived from ConfigDir.
-18
View File
@@ -84,21 +84,3 @@ func (e *Executor) ZoneSerial(ctx context.Context, namespace, pod, zone, view st
}
return 0, nil
}
// ApexNS returns the zone's currently published apex NS names, queried from the
// local server so the operator can converge the RRset rather than append to it.
func (e *Executor) ApexNS(ctx context.Context, namespace, pod, zone string) ([]string, error) {
out, err := e.Exec(ctx, namespace, pod, []string{DigBin, "+short", "@127.0.0.1", dot(zone), "NS"}, "")
if err != nil {
return nil, fmt.Errorf("query apex NS of %s: %w (out: %s)", zone, err, out)
}
var ns []string
for _, line := range strings.Split(out, "\n") {
// dig +short prints one fully-qualified name per line; anything without
// a trailing dot is not an answer.
if line = strings.TrimSpace(line); strings.HasSuffix(line, ".") {
ns = append(ns, line)
}
}
return ns, nil
}