Initial bind-operator: 9 CRDs + controllers
Implements a Kubernetes operator that manages fleets of BIND9 servers declaratively, using controller-runtime (matching forgebot conventions). - add BindCluster reconciler: StatefulSet (pod-0 primary, secondaries), headless + client Services, rendered named.conf ConfigMap, TSIG keys Secret and rndc control Secret; watches dependent CRs to re-render - add BindTSIGKey reconciler that generates key material into a Secret - add BindZone/DNSRecord reconcilers using fully-dynamic delivery (rndc addzone + TSIG nsupdate against the primary pod) - add BindCatalogZone reconciler so secondaries auto-provision zones - add BindPolicy (RPZ), BindDNSSECPolicy, BindView, BindACL reconcilers - render primary/secondary named.conf variants selected by pod ordinal - generate CRDs, deepcopy and RBAC; add samples mapping the three Puppet roles (authoritative/resolver/external-dns) to three BindClusters - add Makefile, Dockerfile.operator, Woodpecker CI and kind manifests
This commit is contained in:
@@ -0,0 +1,89 @@
|
||||
package bind
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"strings"
|
||||
)
|
||||
|
||||
// RndcConfPath is the operator-managed rndc client config mounted in each pod.
|
||||
const RndcConfPath = "/etc/bind/rndc.conf"
|
||||
|
||||
// Rndc runs `rndc <args...>` on a pod and returns its output.
|
||||
func (e *Executor) Rndc(ctx context.Context, namespace, pod string, args ...string) (string, error) {
|
||||
base := []string{"rndc", "-c", RndcConfPath}
|
||||
return e.Exec(ctx, namespace, pod, append(base, args...), "")
|
||||
}
|
||||
|
||||
// Reconfig reloads named.conf and any newly added/removed zones without a full
|
||||
// restart.
|
||||
func (e *Executor) Reconfig(ctx context.Context, namespace, pod string) error {
|
||||
_, err := e.Rndc(ctx, namespace, pod, "reconfig")
|
||||
return err
|
||||
}
|
||||
|
||||
// AddZone provisions a zone at runtime via `rndc addzone`. config is the inner
|
||||
// zone clause, e.g. `{ type primary; file "db.example"; allow-update { key k; }; };`.
|
||||
func (e *Executor) AddZone(ctx context.Context, namespace, pod, zone, view, config string) error {
|
||||
args := []string{"addzone", zone}
|
||||
if view != "" {
|
||||
args = append(args, "in", view)
|
||||
}
|
||||
args = append(args, config)
|
||||
out, err := e.Rndc(ctx, namespace, pod, args...)
|
||||
if err != nil {
|
||||
// addzone fails if the zone already exists; fall back to modzone so the
|
||||
// operation is idempotent.
|
||||
if strings.Contains(err.Error(), "already exists") || strings.Contains(out, "already exists") {
|
||||
return e.ModZone(ctx, namespace, pod, zone, view, config)
|
||||
}
|
||||
return err
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// ModZone updates an existing runtime-added zone's configuration.
|
||||
func (e *Executor) ModZone(ctx context.Context, namespace, pod, zone, view, config string) error {
|
||||
args := []string{"modzone", zone}
|
||||
if view != "" {
|
||||
args = append(args, "in", view)
|
||||
}
|
||||
args = append(args, config)
|
||||
_, err := e.Rndc(ctx, namespace, pod, args...)
|
||||
return err
|
||||
}
|
||||
|
||||
// DelZone removes a runtime-added zone. A missing zone is treated as success.
|
||||
func (e *Executor) DelZone(ctx context.Context, namespace, pod, zone, view string) error {
|
||||
args := []string{"delzone", zone}
|
||||
if view != "" {
|
||||
args = append(args, "in", view)
|
||||
}
|
||||
out, err := e.Rndc(ctx, namespace, pod, args...)
|
||||
if err != nil && (strings.Contains(err.Error(), "not found") || strings.Contains(out, "not found")) {
|
||||
return nil
|
||||
}
|
||||
return err
|
||||
}
|
||||
|
||||
// ZoneSerial returns the current SOA serial for a zone via `rndc zonestatus`.
|
||||
func (e *Executor) ZoneSerial(ctx context.Context, namespace, pod, zone, view string) (int64, error) {
|
||||
args := []string{"zonestatus", zone}
|
||||
if view != "" {
|
||||
args = append(args, "in", view)
|
||||
}
|
||||
out, err := e.Rndc(ctx, namespace, pod, args...)
|
||||
if err != nil {
|
||||
return 0, err
|
||||
}
|
||||
for _, line := range strings.Split(out, "\n") {
|
||||
line = strings.TrimSpace(line)
|
||||
if strings.HasPrefix(line, "serial:") {
|
||||
var serial int64
|
||||
if _, err := fmt.Sscanf(line, "serial: %d", &serial); err == nil {
|
||||
return serial, nil
|
||||
}
|
||||
}
|
||||
}
|
||||
return 0, nil
|
||||
}
|
||||
Reference in New Issue
Block a user