converge apex NS per record, not by RRset replace
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful

BIND ignores an RRset-wide delete of apex NS, so the previous replace only
appended to the seed placeholder.
This commit is contained in:
2026-09-26 18:50:55 +10:00
parent 4a41cbc427
commit e4ed6c8052
9 changed files with 304 additions and 130 deletions
+18
View File
@@ -84,3 +84,21 @@ func (e *Executor) ZoneSerial(ctx context.Context, namespace, pod, zone, view st
}
return 0, nil
}
// ApexNS returns the zone's currently published apex NS names, queried from the
// local server so the operator can converge the RRset rather than append to it.
func (e *Executor) ApexNS(ctx context.Context, namespace, pod, zone string) ([]string, error) {
out, err := e.Exec(ctx, namespace, pod, []string{DigBin, "+short", "@127.0.0.1", dot(zone), "NS"}, "")
if err != nil {
return nil, fmt.Errorf("query apex NS of %s: %w (out: %s)", zone, err, out)
}
var ns []string
for _, line := range strings.Split(out, "\n") {
// dig +short prints one fully-qualified name per line; anything without
// a trailing dot is not an answer.
if line = strings.TrimSpace(line); strings.HasSuffix(line, ".") {
ns = append(ns, line)
}
}
return ns, nil
}