Skip to content

fix(bind9instance): roll BIND pods when their rendered config changes - #520

Merged
ebourgeois merged 1 commit into
mainfrom
fix-config-rollout
Oct 3, 2026
Merged

ebourgeois merged 1 commit into
mainfrom
fix-config-rollout

Conversation

@ebourgeois

Copy link
Copy Markdown
Contributor

fix(bind9instance): roll BIND pods when their rendered config changes

Config changes never reached running BIND pods. The shared cluster
ConfigMap was re-rendered only when the Bind9Cluster generation changed and
that reconcile won a race, and BIND reads named.conf only at start. An
operator upgrade that renders the same spec differently (the key-directory
fix in #518) therefore never reached an existing cluster.

- desired_configmap_for_instance renders the ConfigMap an instance mounts
  (the cluster's shared one, exactly as the cluster reconciler renders it,
  or a standalone instance's own); it is written only when its data differs.
- The pod template carries bindy.firestoned.io/config-hash, the sha256 of
  that data; a changed hash marks the Deployment for update and is patched
  onto the template, which rolls the pods.
- config_drifted makes stale config content, or pods with another hash, a
  reason to run the instance's resource step, which was otherwise skipped
  unless the generation, labels, parent generation or key rotation changed.

Known, not changed here: deployment_needs_update ignores the bind9
container image, and instances sharing a cluster ConfigMap roll together.

Signed-off-by: Erick Bourgeois <erick@jeb.ca>
@ebourgeois
ebourgeois merged commit 80aa9b7 into main Oct 3, 2026
56 checks passed
@ebourgeois
ebourgeois deleted the fix-config-rollout branch October 3, 2026 21:59
ebourgeois added a commit that referenced this pull request Oct 3, 2026
… Deployments

The Deployment update path patched only the API container, labels and
placement. A Deployment created before DNSSEC signing was enabled
therefore never got the dnssec-keys volume, and with key-directory now
pointing at it (#518), BIND had nowhere to keep keys and zones stayed
unsigned. Seen live after rolling onto #518 and #520.

- volumes_missing(): detects a pod volume or bind9 volume mount that the
  operator renders but the running Deployment lacks. It compares by name
  and by (name, mountPath), because the API server adds defaults to the
  stored object.
- The reconcile treats missing volumes as drift, so the resource step
  runs.
- build_volumes_patch(): the update patch carries pod volumes and the
  bind9 container's volumeMounts as strategic-merge `$patch: replace`
  lists, so stale entries are removed instead of left behind.

Tests (volume_convergence): enabling signing on an existing Deployment
needs an update and an identical one does not; the patch carries the
dnssec-keys volume and the bind9 mount as replace lists.

Signed-off-by: Erick Bourgeois <erick@jeb.ca>
ebourgeois added a commit that referenced this pull request Oct 3, 2026
… Deployments (#521)

The Deployment update path patched only the API container, labels and
placement. A Deployment created before DNSSEC signing was enabled
therefore never got the dnssec-keys volume, and with key-directory now
pointing at it (#518), BIND had nowhere to keep keys and zones stayed
unsigned. Seen live after rolling onto #518 and #520.

- volumes_missing(): detects a pod volume or bind9 volume mount that the
  operator renders but the running Deployment lacks. It compares by name
  and by (name, mountPath), because the API server adds defaults to the
  stored object.
- The reconcile treats missing volumes as drift, so the resource step
  runs.
- build_volumes_patch(): the update patch carries pod volumes and the
  bind9 container's volumeMounts as strategic-merge `$patch: replace`
  lists, so stale entries are removed instead of left behind.

Tests (volume_convergence): enabling signing on an existing Deployment
needs an update and an identical one does not; the patch carries the
dnssec-keys volume and the bind9 mount as replace lists.

Signed-off-by: Erick Bourgeois <erick@jeb.ca>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants