Initial bind-operator: 9 CRDs + controllers
Implements a Kubernetes operator that manages fleets of BIND9 servers declaratively, using controller-runtime (matching forgebot conventions). - add BindCluster reconciler: StatefulSet (pod-0 primary, secondaries), headless + client Services, rendered named.conf ConfigMap, TSIG keys Secret and rndc control Secret; watches dependent CRs to re-render - add BindTSIGKey reconciler that generates key material into a Secret - add BindZone/DNSRecord reconcilers using fully-dynamic delivery (rndc addzone + TSIG nsupdate against the primary pod) - add BindCatalogZone reconciler so secondaries auto-provision zones - add BindPolicy (RPZ), BindDNSSECPolicy, BindView, BindACL reconcilers - render primary/secondary named.conf variants selected by pod ordinal - generate CRDs, deepcopy and RBAC; add samples mapping the three Puppet roles (authoritative/resolver/external-dns) to three BindClusters - add Makefile, Dockerfile.operator, Woodpecker CI and kind manifests
This commit is contained in:
@@ -0,0 +1,26 @@
|
||||
---
|
||||
# Split-horizon example: an internal view answering RFC1918 clients and a
|
||||
# default external view. Bind a zone to a view via BindZone.spec.viewRef.
|
||||
apiVersion: bind.unkin.net/v1alpha1
|
||||
kind: BindView
|
||||
metadata:
|
||||
name: internal
|
||||
namespace: bind-auth
|
||||
spec:
|
||||
clusterRef: auth
|
||||
order: 10
|
||||
matchClients:
|
||||
- internal-nets
|
||||
recursion: false
|
||||
---
|
||||
apiVersion: bind.unkin.net/v1alpha1
|
||||
kind: BindView
|
||||
metadata:
|
||||
name: external
|
||||
namespace: bind-auth
|
||||
spec:
|
||||
clusterRef: auth
|
||||
order: 100
|
||||
matchClients:
|
||||
- any
|
||||
recursion: false
|
||||
Reference in New Issue
Block a user