Fix zone provisioning: seed glue + IP primaries
Two bugs made every provisioned zone fail to load: 1. The seed zone's apex NS (ns1.<zone>) is in-zone but had no address record, so BIND check-integrity refused to load it and rndc addzone reverted. Add a glue A record pointing at the primary pod IP. 2. Secondaries rendered primaries/default-primaries with the primary's DNS name, but BIND only accepts IP addresses there (it read the name as a remote-servers list and failed config load, crash-looping the secondary). Render the primary pod IP instead, and watch Pods so the config re-renders when that IP appears or changes. - bind.WriteSeedZone writes 'ns1 IN A <primaryIP>' glue - controllers resolve primaryPodIP and pass it to the seed (requeue if the primary has no IP yet) - BindCluster renders PrimaryAddress from pod-0's IP and watches Pods - render omits catalog primaries when the IP is unknown (no empty list)
This commit is contained in:
@@ -87,6 +87,18 @@ func primaryReady(ctx context.Context, c client.Client, cluster *bindv1alpha1.Bi
|
||||
return false
|
||||
}
|
||||
|
||||
// primaryPodIP returns the pod IP of a cluster's primary pod (ordinal 0), or an
|
||||
// empty string if the pod has no IP yet. BIND's primaries/default-primaries
|
||||
// only accept IP addresses (not hostnames), and zone seeding needs the address
|
||||
// for glue, so the operator resolves the pod IP rather than using a DNS name.
|
||||
func primaryPodIP(ctx context.Context, c client.Client, cluster *bindv1alpha1.BindCluster) string {
|
||||
var pod corev1.Pod
|
||||
if err := c.Get(ctx, client.ObjectKey{Namespace: cluster.Namespace, Name: primaryPodName(cluster.Name)}, &pod); err != nil {
|
||||
return ""
|
||||
}
|
||||
return pod.Status.PodIP
|
||||
}
|
||||
|
||||
// resolveTSIG reads the material of a BindTSIGKey into TSIG credentials.
|
||||
func resolveTSIG(ctx context.Context, c client.Client, namespace, keyRef string) (bind.TSIGCreds, error) {
|
||||
var creds bind.TSIGCreds
|
||||
|
||||
Reference in New Issue
Block a user