deploy: enable rfc2136 plugin for all 84 production zones
Wires the custom CoreDNS image (built via coredns/Dockerfile, source
includes git.supported.systems/rsp2k/coredns-rfc2136) into production:
- docker-compose.yml: switch coredns service from upstream image pin
to a build target. New `image: coredns-rfc2136:${COREDNS_IMAGE_TAG}`
is locally-built; `up -d coredns` triggers the build.
- .env: COREDNS_IMAGE_TAG=2026.05.21 (CalVer). Old COREDNS_IMAGE kept
as a comment for emergency rollback to upstream 1.11.3.
- Corefile: new rfc2136 directive inside (common) snippet enumerating
all 84 zones currently in zones/. Plugin is now in the chain for
every server block (plain DNS, DoT, DoH). UPDATE opcode lands in
the plugin handler; auto-commit on, CalVer SOA serial bumping on,
zones-dir /zones matches the existing bind-mount.
TSIG key is read from ${ACME_TSIG_SECRET} which lives in .env.local
(gitignored). Production deployment needs that file synced to dell01
separately.
This commit DOESN'T trigger the deployment by itself -- the image
must be built on dell01 and the container recreated to apply.
This commit is contained in:
parent
1b87bbb2c0
commit
3720cd2885
3 changed files with 27 additions and 2 deletions
7
.env
7
.env
|
|
@ -1,6 +1,11 @@
|
|||
COMPOSE_PROJECT_NAME=coredns
|
||||
|
||||
# CoreDNS image pin — use a digest in real deploys
|
||||
# Custom CoreDNS image tag (CalVer). Built locally via `docker compose
|
||||
# build coredns` using ./coredns/Dockerfile; pulls plugins from the
|
||||
# referenced git repos at build time. Bump this when re-rolling.
|
||||
COREDNS_IMAGE_TAG=2026.05.21
|
||||
# Legacy pin (no longer the active image; kept for emergency rollback
|
||||
# to upstream CoreDNS if the custom build needs to be reverted).
|
||||
COREDNS_IMAGE=coredns/coredns:1.11.3
|
||||
|
||||
# Host ports. systemd-resolved usually binds 53, so default to 5353.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue