e4ed6c8052
BIND ignores an RRset-wide delete of apex NS, so the previous replace only appended to the seed placeholder.
105 lines
3.4 KiB
Go
105 lines
3.4 KiB
Go
package bind
|
|
|
|
import (
|
|
"context"
|
|
"fmt"
|
|
"strings"
|
|
)
|
|
|
|
// Rndc runs `rndc <args...>` on a pod and returns its output.
|
|
func (e *Executor) Rndc(ctx context.Context, namespace, pod string, args ...string) (string, error) {
|
|
base := []string{RndcBin, "-c", RndcConfPath}
|
|
return e.Exec(ctx, namespace, pod, append(base, args...), "")
|
|
}
|
|
|
|
// Reconfig reloads named.conf and any newly added/removed zones without a full
|
|
// restart.
|
|
func (e *Executor) Reconfig(ctx context.Context, namespace, pod string) error {
|
|
_, err := e.Rndc(ctx, namespace, pod, "reconfig")
|
|
return err
|
|
}
|
|
|
|
// AddZone provisions a zone at runtime via `rndc addzone`. config is the inner
|
|
// zone clause, e.g. `{ type primary; file "db.example"; allow-update { key k; }; };`.
|
|
func (e *Executor) AddZone(ctx context.Context, namespace, pod, zone, view, config string) error {
|
|
args := []string{"addzone", zone}
|
|
if view != "" {
|
|
args = append(args, "in", view)
|
|
}
|
|
args = append(args, config)
|
|
out, err := e.Rndc(ctx, namespace, pod, args...)
|
|
if err != nil {
|
|
// addzone fails if the zone already exists; fall back to modzone so the
|
|
// operation is idempotent.
|
|
if strings.Contains(err.Error(), "already exists") || strings.Contains(out, "already exists") {
|
|
return e.ModZone(ctx, namespace, pod, zone, view, config)
|
|
}
|
|
return err
|
|
}
|
|
return nil
|
|
}
|
|
|
|
// ModZone updates an existing runtime-added zone's configuration.
|
|
func (e *Executor) ModZone(ctx context.Context, namespace, pod, zone, view, config string) error {
|
|
args := []string{"modzone", zone}
|
|
if view != "" {
|
|
args = append(args, "in", view)
|
|
}
|
|
args = append(args, config)
|
|
_, err := e.Rndc(ctx, namespace, pod, args...)
|
|
return err
|
|
}
|
|
|
|
// DelZone removes a runtime-added zone. A missing zone is treated as success.
|
|
func (e *Executor) DelZone(ctx context.Context, namespace, pod, zone, view string) error {
|
|
args := []string{"delzone", zone}
|
|
if view != "" {
|
|
args = append(args, "in", view)
|
|
}
|
|
out, err := e.Rndc(ctx, namespace, pod, args...)
|
|
if err != nil && (strings.Contains(err.Error(), "not found") || strings.Contains(out, "not found")) {
|
|
return nil
|
|
}
|
|
return err
|
|
}
|
|
|
|
// ZoneSerial returns the current SOA serial for a zone via `rndc zonestatus`.
|
|
func (e *Executor) ZoneSerial(ctx context.Context, namespace, pod, zone, view string) (int64, error) {
|
|
args := []string{"zonestatus", zone}
|
|
if view != "" {
|
|
args = append(args, "in", view)
|
|
}
|
|
out, err := e.Rndc(ctx, namespace, pod, args...)
|
|
if err != nil {
|
|
return 0, err
|
|
}
|
|
for _, line := range strings.Split(out, "\n") {
|
|
line = strings.TrimSpace(line)
|
|
if strings.HasPrefix(line, "serial:") {
|
|
var serial int64
|
|
if _, err := fmt.Sscanf(line, "serial: %d", &serial); err == nil {
|
|
return serial, nil
|
|
}
|
|
}
|
|
}
|
|
return 0, nil
|
|
}
|
|
|
|
// ApexNS returns the zone's currently published apex NS names, queried from the
|
|
// local server so the operator can converge the RRset rather than append to it.
|
|
func (e *Executor) ApexNS(ctx context.Context, namespace, pod, zone string) ([]string, error) {
|
|
out, err := e.Exec(ctx, namespace, pod, []string{DigBin, "+short", "@127.0.0.1", dot(zone), "NS"}, "")
|
|
if err != nil {
|
|
return nil, fmt.Errorf("query apex NS of %s: %w (out: %s)", zone, err, out)
|
|
}
|
|
var ns []string
|
|
for _, line := range strings.Split(out, "\n") {
|
|
// dig +short prints one fully-qualified name per line; anything without
|
|
// a trailing dot is not an answer.
|
|
if line = strings.TrimSpace(line); strings.HasSuffix(line, ".") {
|
|
ns = append(ns, line)
|
|
}
|
|
}
|
|
return ns, nil
|
|
}
|