Repository navigation
fix(bind9instance): converge pod volumes and bind9 mounts on existing Deployments - #521
Merged
Merged
Conversation
… Deployments The Deployment update path patched only the API container, labels and placement. A Deployment created before DNSSEC signing was enabled therefore never got the dnssec-keys volume, and with key-directory now pointing at it (#518), BIND had nowhere to keep keys and zones stayed unsigned. Seen live after rolling onto #518 and #520. - volumes_missing(): detects a pod volume or bind9 volume mount that the operator renders but the running Deployment lacks. It compares by name and by (name, mountPath), because the API server adds defaults to the stored object. - The reconcile treats missing volumes as drift, so the resource step runs. - build_volumes_patch(): the update patch carries pod volumes and the bind9 container's volumeMounts as strategic-merge `$patch: replace` lists, so stale entries are removed instead of left behind. Tests (volume_convergence): enabling signing on an existing Deployment needs an update and an identical one does not; the patch carries the dnssec-keys volume and the bind9 mount as replace lists. Signed-off-by: Erick Bourgeois <erick@jeb.ca>
dgunzy
approved these changes
Oct 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The Deployment update path patched only the API container, labels and
placement. A Deployment created before DNSSEC signing was enabled
therefore never got the dnssec-keys volume, and with key-directory now
pointing at it (#518), BIND had nowhere to keep keys and zones stayed
unsigned. Seen live after rolling onto #518 and #520.
operator renders but the running Deployment lacks. It compares by name
and by (name, mountPath), because the API server adds defaults to the
stored object.
runs.
bind9 container's volumeMounts as strategic-merge
$patch: replacelists, so stale entries are removed instead of left behind.
Tests (volume_convergence): enabling signing on an existing Deployment
needs an update and an identical one does not; the patch carries the
dnssec-keys volume and the bind9 mount as replace lists.
Signed-off-by: Erick Bourgeois erick@jeb.ca