fb103a9e95
Two bugs made every provisioned zone fail to load: 1. The seed zone's apex NS (ns1.<zone>) is in-zone but had no address record, so BIND check-integrity refused to load it and rndc addzone reverted. Add a glue A record pointing at the primary pod IP. 2. Secondaries rendered primaries/default-primaries with the primary's DNS name, but BIND only accepts IP addresses there (it read the name as a remote-servers list and failed config load, crash-looping the secondary). Render the primary pod IP instead, and watch Pods so the config re-renders when that IP appears or changes. - bind.WriteSeedZone writes 'ns1 IN A <primaryIP>' glue - controllers resolve primaryPodIP and pass it to the seed (requeue if the primary has no IP yet) - BindCluster renders PrimaryAddress from pod-0's IP and watches Pods - render omits catalog primaries when the IP is unknown (no empty list)
108 lines
4.0 KiB
Go
108 lines
4.0 KiB
Go
package bind
|
|
|
|
import (
|
|
"strings"
|
|
"testing"
|
|
|
|
bindv1alpha1 "git.unkin.net/unkin/bind-operator/api/v1alpha1"
|
|
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
|
|
)
|
|
|
|
func newCluster(mode bindv1alpha1.BindMode) *bindv1alpha1.BindCluster {
|
|
return &bindv1alpha1.BindCluster{
|
|
ObjectMeta: metav1.ObjectMeta{Name: "auth", Namespace: "dns"},
|
|
Spec: bindv1alpha1.BindClusterSpec{Mode: mode, Replicas: 3},
|
|
}
|
|
}
|
|
|
|
func TestRenderResolverEnablesRecursion(t *testing.T) {
|
|
primary, secondary := RenderNamedConf(RenderInput{Cluster: newCluster(bindv1alpha1.ModeResolver)})
|
|
if !strings.Contains(primary, "recursion yes;") {
|
|
t.Fatalf("resolver primary should enable recursion:\n%s", primary)
|
|
}
|
|
if !strings.Contains(secondary, "recursion yes;") {
|
|
t.Fatalf("resolver secondary should enable recursion")
|
|
}
|
|
}
|
|
|
|
func TestRenderAuthoritativeDisablesRecursion(t *testing.T) {
|
|
primary, _ := RenderNamedConf(RenderInput{Cluster: newCluster(bindv1alpha1.ModeAuthoritative)})
|
|
if !strings.Contains(primary, "recursion no;") {
|
|
t.Fatalf("authoritative should disable recursion:\n%s", primary)
|
|
}
|
|
if !strings.Contains(primary, "allow-new-zones yes;") {
|
|
t.Fatalf("authoritative should allow new zones for dynamic provisioning")
|
|
}
|
|
}
|
|
|
|
func TestRenderCatalogOnSecondaryOnly(t *testing.T) {
|
|
in := RenderInput{
|
|
Cluster: newCluster(bindv1alpha1.ModeAuthoritative),
|
|
Catalog: &bindv1alpha1.BindCatalogZone{Spec: bindv1alpha1.BindCatalogZoneSpec{ZoneName: "catalog.internal", DefaultPrimaries: []string{"10.0.0.1"}}},
|
|
PrimaryAddress: "auth-0.auth-headless.dns.svc.cluster.local",
|
|
}
|
|
primary, secondary := RenderNamedConf(in)
|
|
if strings.Contains(primary, "catalog-zones") {
|
|
t.Fatalf("primary must not consume the catalog it publishes:\n%s", primary)
|
|
}
|
|
if !strings.Contains(secondary, "catalog-zones") {
|
|
t.Fatalf("secondary must consume the catalog zone:\n%s", secondary)
|
|
}
|
|
if !strings.Contains(secondary, "type secondary;") {
|
|
t.Fatalf("secondary must declare the catalog zone as a secondary")
|
|
}
|
|
}
|
|
|
|
func TestRenderCatalogOmittedWhenPrimaryIPUnknown(t *testing.T) {
|
|
// Primary IP not known yet and no explicit default-primaries: the secondary
|
|
// must not emit a catalog-zones / secondary catalog zone with an empty
|
|
// primaries list (which BIND rejects at config load).
|
|
in := RenderInput{
|
|
Cluster: newCluster(bindv1alpha1.ModeAuthoritative),
|
|
Catalog: &bindv1alpha1.BindCatalogZone{Spec: bindv1alpha1.BindCatalogZoneSpec{ZoneName: "catalog.internal"}},
|
|
PrimaryAddress: "",
|
|
}
|
|
_, secondary := RenderNamedConf(in)
|
|
if strings.Contains(secondary, "catalog-zones") || strings.Contains(secondary, "primaries {") {
|
|
t.Fatalf("secondary must omit catalog primaries when the primary IP is unknown:\n%s", secondary)
|
|
}
|
|
}
|
|
|
|
func TestRenderCatalogUsesPrimaryIP(t *testing.T) {
|
|
in := RenderInput{
|
|
Cluster: newCluster(bindv1alpha1.ModeAuthoritative),
|
|
Catalog: &bindv1alpha1.BindCatalogZone{Spec: bindv1alpha1.BindCatalogZoneSpec{ZoneName: "catalog.internal"}},
|
|
PrimaryAddress: "10.42.0.7",
|
|
}
|
|
_, secondary := RenderNamedConf(in)
|
|
if !strings.Contains(secondary, "primaries { 10.42.0.7; }") {
|
|
t.Fatalf("secondary should point primaries at the primary pod IP:\n%s", secondary)
|
|
}
|
|
}
|
|
|
|
func TestRenderACL(t *testing.T) {
|
|
in := RenderInput{
|
|
Cluster: newCluster(bindv1alpha1.ModeAuthoritative),
|
|
ACLs: []bindv1alpha1.BindACL{{
|
|
ObjectMeta: metav1.ObjectMeta{Name: "internal"},
|
|
Spec: bindv1alpha1.BindACLSpec{Entries: []string{"10.0.0.0/8", "192.168.0.0/16"}},
|
|
}},
|
|
}
|
|
primary, _ := RenderNamedConf(in)
|
|
if !strings.Contains(primary, `acl "internal" { 10.0.0.0/8; 192.168.0.0/16; };`) {
|
|
t.Fatalf("ACL not rendered correctly:\n%s", primary)
|
|
}
|
|
}
|
|
|
|
func TestCatalogHashStable(t *testing.T) {
|
|
// SHA-1 of the wire format of "example.com" is well-defined and stable.
|
|
h1 := catalogHash("example.com")
|
|
h2 := catalogHash("example.com.")
|
|
if h1 != h2 {
|
|
t.Fatalf("trailing dot should not change hash: %s vs %s", h1, h2)
|
|
}
|
|
if len(h1) != 40 {
|
|
t.Fatalf("expected 40-char hex sha1, got %d: %s", len(h1), h1)
|
|
}
|
|
}
|