Skip to content

Support migration windows for BIND9 - #1428

Open
beagles wants to merge 4 commits into
openstack-k8s-operators:mainfrom
beagles:designate-staged-migration
Open

Support migration windows for BIND9#1428
beagles wants to merge 4 commits into
openstack-k8s-operators:mainfrom
beagles:designate-staged-migration

Conversation

@beagles

@beagles beagles commented Jun 30, 2026

Copy link
Copy Markdown
Contributor

The IPs for the BIND9 servers may be in external registries or in other DNS configuration for zone delegation via glue records.

This change is part of a series to verify the steps to maintaining records in both the RHOSO system and the legacy system to allow a staged migration of DNS infrastructure.

Documentation is enhanced to:

  • Update the procedure for maintaining a migration window with legacy BIND9 servers, including a reference to additional steps after the standard adoption.
  • Add tasks to configure and enable the Designate service, including creating a LoadBalancer service for mDNS zone transfers.
  • Refine task names for clarity and removed unnecessary steps related to external binds secret verification.
  • Improve the patch file creation process for Designate CR to include necessary configurations for legacy BIND9 integration.

@openshift-ci

openshift-ci Bot commented Jun 30, 2026

Copy link
Copy Markdown

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@openshift-ci

openshift-ci Bot commented Jun 30, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign holser for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@beagles
beagles force-pushed the designate-staged-migration branch 2 times, most recently from 47dadc6 to 70fa108 Compare June 30, 2026 12:11
@beagles
beagles marked this pull request as ready for review June 30, 2026 12:12
@centosinfra-prod-github-app

Copy link
Copy Markdown

Build failed (check pipeline). Post recheck (without leading slash)
to rerun all jobs. Make sure the failure cause has been resolved before
you rerun jobs.

https://gateway-cloud-softwarefactory.apps.ocp.cloud.ci.centos.org/zuul/t/rdoproject.org/buildset/6d7e808c42ae417f9eb3094b904e5e85

✔️ noop SUCCESS in 0s
✔️ adoption-standalone-to-crc-ceph SUCCESS in 3h 12m 10s
adoption-standalone-to-crc-no-ceph FAILURE in 1h 12m 27s
✔️ adoption-docs-preview SUCCESS in 1m 40s

@jistr jistr left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, adding Katie for docs

@jistr
jistr requested a review from klgill July 2, 2026 13:52

@klgill klgill left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let me know if you have any questions on my edits. Thanks!

Comment thread docs_user/modules/proc_adopting-the-dns-service.adoc Outdated
Comment thread docs_user/modules/proc_adopting-the-dns-service.adoc Outdated
Comment thread docs_user/modules/proc_adopting-the-dns-service.adoc Outdated
Comment thread docs_user/modules/proc_adopting-the-dns-service.adoc Outdated
Comment thread docs_user/modules/proc_adopting-the-dns-service.adoc Outdated
Comment thread docs_user/modules/proc_adopting-the-dns-service.adoc Outdated
Comment thread docs_user/modules/proc_adopting-the-dns-service.adoc Outdated
Comment thread docs_user/modules/proc_adopting-the-dns-service.adoc Outdated
Comment thread docs_user/modules/proc_adopting-the-dns-service.adoc Outdated
Comment thread docs_user/modules/proc_adopting-the-dns-service.adoc Outdated
The IPs for the BIND9 servers may be in external registries
or in other DNS configuration for zone delegation via glue records.

This change is part of a series to verify the steps to maintaining
records in both the RHOSO system and the legacy system to allow a staged
migration of DNS infrastructure.

Documentation is enhanced to:

- Update the procedure for maintaining a migration window with legacy
  BIND9 servers, including a reference to additional steps after the
  standard adoption.
- Add tasks to configure and enable the Designate service, including
  creating a LoadBalancer service for mDNS zone transfers.
- Refine task names for clarity and removed unnecessary steps related to
  external binds secret verification.
- Improve the patch file creation process for Designate CR to include
  necessary configurations for legacy BIND9 integration.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@beagles
beagles force-pushed the designate-staged-migration branch from b4162ac to 6d67b8f Compare July 14, 2026 11:10
@centosinfra-prod-github-app

Copy link
Copy Markdown

Build failed (check pipeline). Post recheck (without leading slash)
to rerun all jobs. Make sure the failure cause has been resolved before
you rerun jobs.

https://gateway-cloud-softwarefactory.apps.ocp.cloud.ci.centos.org/zuul/t/rdoproject.org/buildset/3b3583e7334c4e8f99f79dc0f6f86e6b

✔️ noop SUCCESS in 0s
✔️ adoption-standalone-to-crc-ceph SUCCESS in 3h 15m 37s
adoption-standalone-to-crc-no-ceph FAILURE in 1h 20m 27s
✔️ adoption-docs-preview SUCCESS in 1m 47s

beagles and others added 3 commits July 22, 2026 16:34
The IPs for the BIND9 servers may be in external registries
or in other DNS configuration for zone delegation via glue records.

This change is part of a series to verify the steps to maintaining
records in both the RHOSO system and the legacy system to allow a staged
migration of DNS infrastructure.

Documentation is enhanced to:

- Update the procedure for maintaining a migration window with legacy
  BIND9 servers, including a reference to additional steps after the
  standard adoption.
- Add tasks to configure and enable the Designate service, including
  creating a LoadBalancer service for mDNS zone transfers.
- Refine task names for clarity and removed unnecessary steps related to
  external binds secret verification.
- Improve the patch file creation process for Designate CR to include
  necessary configurations for legacy BIND9 integration.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Move "Maintaining a migration window with legacy BIND9 servers" and
"Completing the BIND9 migration" out of proc_adopting-the-dns-service.adoc
and into their own PROCEDURE modules, following the modular-docs procedure
template instead of embedding them as sub-headings in another procedure.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…rification test

- Fix 'desginate' typo in systemctl restart command in migration-window doc
- Use plural CRD name (designates.designate.openstack.org) in docs to match tests
- Add missing -i flag to sed command in designate_external_binds.yaml
- Add RNDC connectivity verification task to designate_external_migrate.yaml

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

@klgill klgill left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for restructuring. I fixed some formatting issues and updated the short description of one of the procedures.

= Maintaining a migration window with legacy BIND9 servers

[role="_abstract"]
A complete immediate switchover of all DNS servers to {rhos_long} requires all DNS clients to be updated with the new addresses of the DNS servers. This may be DNS registry entries, `glue records` in other DNS zone tables or configuration in OpenStack servers. In deployments where this cannot be done immediately, this procedure configures the existing DNS servers to be used and updated until all references to them can be migrated to the {rhos_long} DNS services.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
A complete immediate switchover of all DNS servers to {rhos_long} requires all DNS clients to be updated with the new addresses of the DNS servers. This may be DNS registry entries, `glue records` in other DNS zone tables or configuration in OpenStack servers. In deployments where this cannot be done immediately, this procedure configures the existing DNS servers to be used and updated until all references to them can be migrated to the {rhos_long} DNS services.
Transition to {rhos_long} DNS services gradually when a complete, immediate switchover isn't possible. This keeps existing DNS servers active and updated while you migrate external references, registry entries, and client configurations over time.

[role="_abstract"]
A complete immediate switchover of all DNS servers to {rhos_long} requires all DNS clients to be updated with the new addresses of the DNS servers. This may be DNS registry entries, `glue records` in other DNS zone tables or configuration in OpenStack servers. In deployments where this cannot be done immediately, this procedure configures the existing DNS servers to be used and updated until all references to them can be migrated to the {rhos_long} DNS services.

If your {rhos_prev_long} deployment uses BIND9 servers that should continue serving DNS during adoption, follow this procedure after completing the standard {dns_service} adoption. The designate worker sends RNDC commands and DNS NOTIFY messages to the legacy servers, which pull zone data from the mDNS service through AXFR on port 5354.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
If your {rhos_prev_long} deployment uses BIND9 servers that should continue serving DNS during adoption, follow this procedure after completing the standard {dns_service} adoption. The designate worker sends RNDC commands and DNS NOTIFY messages to the legacy servers, which pull zone data from the mDNS service through AXFR on port 5354.
If your {rhos_prev_long} deployment uses BIND9 servers that need to stay active during adoption, follow these steps after completing the standard {dns_service} adoption. The Designate worker sends RNDC commands and DNS NOTIFY messages to your legacy servers, which then fetch zone updates from the mDNS service via AXFR on port 5354.

fi
----
+
where:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
where:
where:

----
+
where:
`CONTROLLER1_SSH`, `CONTROLLER2_SSH`, and `CONTROLLER3_SSH`::

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
`CONTROLLER1_SSH`, `CONTROLLER2_SSH`, and `CONTROLLER3_SSH`::
`CONTROLLER1_SSH`, `CONTROLLER2_SSH`, and `CONTROLLER3_SSH`::

====

+
Reload the BIND9 configuration:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Reload the BIND9 configuration:
. Reload the BIND9 configuration:

The `sed` commands in the shell script example are directed at default deployments. If customizations are made to the deployment, either modify these commands or perform the modifications directly.
====

+

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
+


. Create a LoadBalancer service to expose the mDNS service on the internalapi
network so that the legacy BIND9 servers can perform AXFR zone transfers:
+

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
+
+

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants