dns: exclude k8s/LB ranges from dns-updater; track latest (#485)
Configures the dns-updater record filter (dns-updater#3) so k8s/LB/internal addresses stay out of the authoritative zones. ## Why Hosts publish records the authoritative server should not hold — `*-flannel.1 A 10.42.x`, `*-kube-lb0 A 198.18.200.x`, and the matching reverse PTRs (`200.18.198`, `2.42.10`) — which the daemon WARNs `NOTAUTH`/`bad authentication` on. ## Changes - `DNS_UPDATER_DENY_RANGES=198.18.199.0/24,198.18.200.0/24,10.42.0.0/16,10.43.0.0/16` (pod CIDR, service CIDR, LB VIP pool, .199). - New class params: `deny_ranges` / `allow_ranges` / `deny_domains` / `allow_domains`. - `package_ensure` → `latest` so hosts pick up the filter release (rpm-internal `metadata_expire` is 1h, so no thrash). ## Sequencing Needs dns-updater **#3** merged + a new tag (v0.2.0) so the filter env vars are honored. The env keys are ignored by v0.1.0, so this is safe to merge first — it takes effect when hosts upgrade to v0.2.0. Reviewed-on: #485 Co-authored-by: Ben Vincent <ben@unkin.net> Co-committed-by: Ben Vincent <ben@unkin.net>
This commit was merged in pull request #485.
This commit is contained in:
@@ -23,12 +23,22 @@ class profiles::dns::updater (
|
|||||||
Stdlib::AbsolutePath $state_dir = '/var/lib/dns-updater',
|
Stdlib::AbsolutePath $state_dir = '/var/lib/dns-updater',
|
||||||
Stdlib::AbsolutePath $config_dir = '/etc/dns-updater',
|
Stdlib::AbsolutePath $config_dir = '/etc/dns-updater',
|
||||||
Stdlib::AbsolutePath $master_basedir = lookup('profiles::dns::master::basedir'),
|
Stdlib::AbsolutePath $master_basedir = lookup('profiles::dns::master::basedir'),
|
||||||
# dns-updater daemon (replaces the dns-update shell script).
|
# dns-updater daemon (replaces the dns-update shell script). 'latest' so hosts
|
||||||
String $package_ensure = 'installed',
|
# pick up new releases (e.g. the record filter); rpm-internal metadata_expire
|
||||||
|
# is 1h so this does not thrash.
|
||||||
|
String $package_ensure = 'latest',
|
||||||
Stdlib::AbsolutePath $api_socket = '/run/dns-updater/api.sock',
|
Stdlib::AbsolutePath $api_socket = '/run/dns-updater/api.sock',
|
||||||
String $resync = '10m',
|
String $resync = '10m',
|
||||||
Enum['debug', 'info', 'warn', 'error'] $log_level = 'info',
|
Enum['debug', 'info', 'warn', 'error'] $log_level = 'info',
|
||||||
Boolean $watch_interfaces = true,
|
Boolean $watch_interfaces = true,
|
||||||
|
# Never publish records whose address falls in these ranges: the k8s pod CIDR
|
||||||
|
# (10.42.0.0/16) and service CIDR (10.43.0.0/16), the LB VIP pool
|
||||||
|
# (198.18.200.0/24) and 198.18.199.0/24. Keeps kube-lb0/flannel/etc. out of
|
||||||
|
# the authoritative zones and stops NOTAUTH updates for zones we do not host.
|
||||||
|
Array[String] $deny_ranges = ['198.18.199.0/24', '198.18.200.0/24', '10.42.0.0/16', '10.43.0.0/16'],
|
||||||
|
Array[String] $allow_ranges = [],
|
||||||
|
Array[String] $deny_domains = [],
|
||||||
|
Array[String] $allow_domains = [],
|
||||||
) {
|
) {
|
||||||
|
|
||||||
$state_file = "${state_dir}/applied"
|
$state_file = "${state_dir}/applied"
|
||||||
@@ -103,6 +113,11 @@ class profiles::dns::updater (
|
|||||||
ensure => $package_ensure,
|
ensure => $package_ensure,
|
||||||
}
|
}
|
||||||
|
|
||||||
|
$deny_ranges_str = join($deny_ranges, ',')
|
||||||
|
$allow_ranges_str = join($allow_ranges, ',')
|
||||||
|
$deny_domains_str = join($deny_domains, ',')
|
||||||
|
$allow_domains_str = join($allow_domains, ',')
|
||||||
|
|
||||||
$env_content = @("ENV")
|
$env_content = @("ENV")
|
||||||
# Managed by puppet (profiles::dns::updater).
|
# Managed by puppet (profiles::dns::updater).
|
||||||
DNS_UPDATER_SERVER=${server}
|
DNS_UPDATER_SERVER=${server}
|
||||||
@@ -113,6 +128,10 @@ class profiles::dns::updater (
|
|||||||
DNS_UPDATER_RESYNC=${resync}
|
DNS_UPDATER_RESYNC=${resync}
|
||||||
DNS_UPDATER_WATCH_INTERFACES=${watch_interfaces}
|
DNS_UPDATER_WATCH_INTERFACES=${watch_interfaces}
|
||||||
DNS_UPDATER_LOG_LEVEL=${log_level}
|
DNS_UPDATER_LOG_LEVEL=${log_level}
|
||||||
|
DNS_UPDATER_DENY_RANGES=${deny_ranges_str}
|
||||||
|
DNS_UPDATER_ALLOW_RANGES=${allow_ranges_str}
|
||||||
|
DNS_UPDATER_DENY_DOMAINS=${deny_domains_str}
|
||||||
|
DNS_UPDATER_ALLOW_DOMAINS=${allow_domains_str}
|
||||||
| ENV
|
| ENV
|
||||||
|
|
||||||
file { "${config_dir}/env":
|
file { "${config_dir}/env":
|
||||||
|
|||||||
Reference in New Issue
Block a user