Skip to content

fix(bind9instance): converge pod volumes and bind9 mounts on existing Deployments - #521

Merged
ebourgeois merged 1 commit into
mainfrom
fix-volume-convergence
Oct 3, 2026
Merged

ebourgeois merged 1 commit into
mainfrom
fix-volume-convergence

Conversation

@ebourgeois

Copy link
Copy Markdown
Contributor

The Deployment update path patched only the API container, labels and
placement. A Deployment created before DNSSEC signing was enabled
therefore never got the dnssec-keys volume, and with key-directory now
pointing at it (#518), BIND had nowhere to keep keys and zones stayed
unsigned. Seen live after rolling onto #518 and #520.

  • volumes_missing(): detects a pod volume or bind9 volume mount that the
    operator renders but the running Deployment lacks. It compares by name
    and by (name, mountPath), because the API server adds defaults to the
    stored object.
  • The reconcile treats missing volumes as drift, so the resource step
    runs.
  • build_volumes_patch(): the update patch carries pod volumes and the
    bind9 container's volumeMounts as strategic-merge $patch: replace
    lists, so stale entries are removed instead of left behind.

Tests (volume_convergence): enabling signing on an existing Deployment
needs an update and an identical one does not; the patch carries the
dnssec-keys volume and the bind9 mount as replace lists.

Signed-off-by: Erick Bourgeois erick@jeb.ca

… Deployments

The Deployment update path patched only the API container, labels and
placement. A Deployment created before DNSSEC signing was enabled
therefore never got the dnssec-keys volume, and with key-directory now
pointing at it (#518), BIND had nowhere to keep keys and zones stayed
unsigned. Seen live after rolling onto #518 and #520.

- volumes_missing(): detects a pod volume or bind9 volume mount that the
  operator renders but the running Deployment lacks. It compares by name
  and by (name, mountPath), because the API server adds defaults to the
  stored object.
- The reconcile treats missing volumes as drift, so the resource step
  runs.
- build_volumes_patch(): the update patch carries pod volumes and the
  bind9 container's volumeMounts as strategic-merge `$patch: replace`
  lists, so stale entries are removed instead of left behind.

Tests (volume_convergence): enabling signing on an existing Deployment
needs an update and an identical one does not; the patch carries the
dnssec-keys volume and the bind9 mount as replace lists.

Signed-off-by: Erick Bourgeois <erick@jeb.ca>
@ebourgeois
ebourgeois merged commit 33e58e3 into main Oct 3, 2026
51 checks passed
@ebourgeois
ebourgeois deleted the fix-volume-convergence branch October 3, 2026 23:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants