Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: IDNA awareness in the zone finder #5147

Merged
merged 3 commits into from
Mar 24, 2025

Conversation

lexisother
Copy link
Contributor

Description

Normalise domain names before looking them up in the zone ID mapping.

Fixes #5090

Checklist

  • Unit tests updated
  • End user documentation updated

@k8s-ci-robot k8s-ci-robot added the cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. label Mar 6, 2025
@k8s-ci-robot
Copy link
Contributor

Welcome @lexisother!

It looks like this is your first PR to kubernetes-sigs/external-dns 🎉. Please refer to our pull request process documentation to help your PR have a smooth ride to approval.

You will be prompted by a bot to use commands during the review process. Do not be afraid to follow the prompts! It is okay to experiment. Here is the bot commands documentation.

You can also check if kubernetes-sigs/external-dns has its own contribution guidelines.

You may want to refer to our testing guide if you run into trouble with your tests not passing.

If you are having difficulty getting your pull request seen, please follow the recommended escalation practices. Also, for tips and tricks in the contribution process you may want to read the Kubernetes contributor cheat sheet. We want to make sure your contribution gets all the attention it needs!

Thank you, and welcome to Kubernetes. 😃

@k8s-ci-robot
Copy link
Contributor

Hi @lexisother. Thanks for your PR.

I'm waiting for a kubernetes-sigs member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@k8s-ci-robot k8s-ci-robot added needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Mar 6, 2025
@ivankatliarchuk
Copy link
Contributor

/ok-to-test

@k8s-ci-robot k8s-ci-robot added ok-to-test Indicates a non-member PR verified by an org member that is safe to test. and removed needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. labels Mar 6, 2025
@ivankatliarchuk
Copy link
Contributor

/label tide/merge-method-squash

@k8s-ci-robot k8s-ci-robot added the tide/merge-method-squash Denotes a PR that should be squashed by tide when it merges. label Mar 6, 2025
@lexisother
Copy link
Contributor Author

@ivankatliarchuk Added a test for the warning log, hope it's fine like this!

@ivankatliarchuk
Copy link
Contributor

Nice one. I'll try to execute smoke test on my side. If you have a working setup, could share results here as well.

@lexisother
Copy link
Contributor Author

I don't have many results to share other than the before/after logs on my own cluster 😅

Without my changes:

DEBU[0004] Skipping record a.xn--ccka2b6azt.xn--q9jyb4c because no hosted zone matching record DNS Name was detected
DEBU[0004] Skipping record a.a.xn--ccka2b6azt.xn--q9jyb4c because no hosted zone matching record DNS Name was detected

With my changes:

time="2025-03-04T00:57:46Z" level=info msg="Changing record." action=CREATE record=a.xn--ccka2b6azt.xn--q9jyb4c ttl=1 type=A zone=49619bc8e3ea12578435348ffa4707f1
time="2025-03-04T00:57:46Z" level=info msg="Changing record." action=CREATE record=a.a.xn--ccka2b6azt.xn--q9jyb4c ttl=1 type=TXT zone=49619bc8e3ea12578435348ffa4707f1

@ivankatliarchuk
Copy link
Contributor

ivankatliarchuk commented Mar 7, 2025

So the solution seems legit. I did a research and found AWS related docs, they suggest to do exactly that.

If you're using the Route 53 API or one of the AWS SDKs, you can programmatically convert a Unicode value to Punycode.

@ivankatliarchuk
Copy link
Contributor

Any chance you share you external-dns arguments as well?

@lexisother
Copy link
Contributor Author

Yep! Sorry for the delayed response! 😅
Here's my options:

  values:
    image:
      registry: ghcr.io
      repository: lexisother/external-dns
      tag: idna-fix-3
      pullSecrets:
        - ghcr-login-secret
    txtPrefix: "%{record_type}."
    provider: cloudflare
    cloudflare:
      secretName: external-dns
      proxied: false

@ivankatliarchuk
Copy link
Contributor

It's a bit tricky to undersand to be honest. Could you have a look/check deployment manifest in kubernetes? Need only arguments, not yaml values sry from helm.

Something like

args:
 - --source=service
  - --registry=txt
  - --policy=upsert
  - --provider=cloudflare

@lexisother
Copy link
Contributor Author

Here's the args from the resulting deployment:

      args:
        - '--metrics-address=:7979'
        - '--log-level=info'
        - '--log-format=text'
        - '--policy=upsert-only'
        - '--provider=cloudflare'
        - '--registry=txt'
        - '--interval=1m'
        - '--txt-prefix=%{record_type}.'
        - '--source=service'
        - '--source=ingress'
        - '--cloudflare-dns-records-per-page=100'

@ivankatliarchuk
Copy link
Contributor

I was not able to test this PR due to bug that was fixed in this PR #5146. Any chance you rebase your changes so I could do final checks?

@lexisother
Copy link
Contributor Author

@ivankatliarchuk Done.

Copy link
Contributor

@ivankatliarchuk ivankatliarchuk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

cc: @mloiseleur

@k8s-ci-robot k8s-ci-robot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Mar 17, 2025
@mloiseleur
Copy link
Collaborator

/lgtm
/approve

@k8s-ci-robot
Copy link
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: ivankatliarchuk, mloiseleur

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@k8s-ci-robot k8s-ci-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Mar 24, 2025
@k8s-ci-robot k8s-ci-robot merged commit 25333a4 into kubernetes-sigs:master Mar 24, 2025
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved Indicates a PR has been approved by an approver from all required OWNERS files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. size/S Denotes a PR that changes 10-29 lines, ignoring generated files. tide/merge-method-squash Denotes a PR that should be squashed by tide when it merges.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

external-dns is ignoring punycode domains
4 participants