Skip to content

Commit 5fa90f2

Browse files
author
root
committed
Allow designate rndc for all nodes (SOC-10339)
With designate enabled, all Bind servers act as slaves for designate created zones. These zones are created via rndc addzone from designate server(s). Adding permissions and key for allowing rndc access.
1 parent 44b7cf1 commit 5fa90f2

File tree

2 files changed

+4
-4
lines changed

2 files changed

+4
-4
lines changed

chef/cookbooks/bind9/recipes/default.rb

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -355,15 +355,15 @@ def make_zone(zone)
355355
notifies :reload, "service[bind9]"
356356
end
357357

358-
if node[:dns][:enable_designate] && node[:dns][:master]
358+
if node[:dns][:enable_designate]
359359
template "/etc/named.d/designate-rndc-access.conf" do
360360
source "designate-rndc-access.conf.erb"
361361
mode 0o640
362362
owner "root"
363363
group bindgroup
364364
variables(
365365
rndc_key: node[:dns][:designate_rndc_key],
366-
master_ip: admin_network.address,
366+
admin_ip: admin_network.address,
367367
admin_subnet: IP::IP4.netmask_to_subnet(admin_network.netmask),
368368
admin_network: admin_network.subnet
369369
)
@@ -415,7 +415,7 @@ def make_zone(zone)
415415
allow_transfer: allow_transfer,
416416
ipaddresses: ipaddresses,
417417
ip6addresses: ip6addresses,
418-
enable_designate: node[:dns][:enable_designate] && node[:dns][:master]
418+
enable_designate: node[:dns][:enable_designate]
419419
)
420420
notifies :restart, "service[bind9]", :immediately
421421
end

chef/cookbooks/bind9/templates/default/designate-rndc-access.conf.erb

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,5 +7,5 @@ controls {
77
# listen on the admin interface and
88
# allow access via the designate-key
99
# from ips of admin_network
10-
inet <%= @master_ip -%> allow { <%= @admin_network -%>/<%= @admin_subnet -%>; } keys { designate-key; };
10+
inet <%= @admin_ip -%> allow { <%= @admin_network -%>/<%= @admin_subnet -%>; } keys { designate-key; };
1111
};

0 commit comments

Comments
 (0)