fe5fbdaf6d
Implements a Kubernetes operator that manages fleets of BIND9 servers declaratively, using controller-runtime (matching forgebot conventions). - add BindCluster reconciler: StatefulSet (pod-0 primary, secondaries), headless + client Services, rendered named.conf ConfigMap, TSIG keys Secret and rndc control Secret; watches dependent CRs to re-render - add BindTSIGKey reconciler that generates key material into a Secret - add BindZone/DNSRecord reconcilers using fully-dynamic delivery (rndc addzone + TSIG nsupdate against the primary pod) - add BindCatalogZone reconciler so secondaries auto-provision zones - add BindPolicy (RPZ), BindDNSSECPolicy, BindView, BindACL reconcilers - render primary/secondary named.conf variants selected by pod ordinal - generate CRDs, deepcopy and RBAC; add samples mapping the three Puppet roles (authoritative/resolver/external-dns) to three BindClusters - add Makefile, Dockerfile.operator, Woodpecker CI and kind manifests
27 lines
533 B
YAML
27 lines
533 B
YAML
---
|
|
# Split-horizon example: an internal view answering RFC1918 clients and a
|
|
# default external view. Bind a zone to a view via BindZone.spec.viewRef.
|
|
apiVersion: bind.unkin.net/v1alpha1
|
|
kind: BindView
|
|
metadata:
|
|
name: internal
|
|
namespace: bind-auth
|
|
spec:
|
|
clusterRef: auth
|
|
order: 10
|
|
matchClients:
|
|
- internal-nets
|
|
recursion: false
|
|
---
|
|
apiVersion: bind.unkin.net/v1alpha1
|
|
kind: BindView
|
|
metadata:
|
|
name: external
|
|
namespace: bind-auth
|
|
spec:
|
|
clusterRef: auth
|
|
order: 100
|
|
matchClients:
|
|
- any
|
|
recursion: false
|