The halb published service CNAMEs (git.unkin.net, dashboard.ceph.unkin.net, ...)
with a bare target label ("au-syd1-prod-halb-vrrp"). dns-updater parses the
record value with no $ORIGIN, so a bare label becomes root-absolute
("au-syd1-prod-halb-vrrp.") and dead-ends in NXDOMAIN -- breaking every
halb-fronted name once the k8s bind became authoritative.
Emit fully-qualified targets (trailing dot) for both the vrrp and non-vrrp
CNAMEs, matching the FQDN value dns-updater expects:
- au-syd1-prod-halb-vrrp.<domain>. and au-syd1-prod-halb.<domain>.
Replace deprecated dalen-puppetdbquery module with native puppetdb_query
function using PQL syntax to resolve URI.escape compatibility issues.
This is required to migrated to Puppet 8 (and kubernetes).
Changes:
- Remove dalen-puppetdbquery dependency from Puppetfile
- Replace query_nodes() calls with puppetdb_query() using PQL syntax
- Update 27 function calls across 18 Puppet manifests
- Maintain equivalent functionality with improved compatibility
Reviewed-on: #457
- manage the unkin.net domain
- ensure forwarding for unkin.net
- split domain from cname list and set zone correctly
- add fafflix to cnames list for haproxy2
Reviewed-on: #347
- update keepalived module to 5.1.0
- add keepalived::vrrp::* to be deep merged in hiera
- add vrrp dns configuration
- add vrrp instance/script to halb in syd1