Skip to content

Custom domain gets an ingress rule and a certificate request before anything checks the DNS points at us #307

Description

@v0l

Setting custom_domain is validated for syntax only — validate_custom_domain (lnvps_api/src/api/apps.rs:816, tests at :1124) rejects ports, paths, schemes and malformed labels, and nothing resolves the name. The operator then adds the rule and a second TLS block with its own issuer annotation unconditionally (custom-domain branch of build_ingress, lnvps_operator/src/app_deployments.rs:882).

A customer who sets a domain before pointing it at us gets an ingress rule that cannot serve and an HTTP-01 challenge that cannot be solved, retried on every reconcile. Let's Encrypt counts failed validations against a separate limit, and the deployment carries a permanently pending certificate with no signal about why.

Wanted

DNS-probe the custom domain before creating its ingress rule or requesting its certificate.

  • Probe at set time, and re-probe on reconcile for a domain that is held rather than refused.
  • Only add the rule and the TLS block once the name resolves to us.
  • Surface pending-DNS vs live to the customer. The silent pending certificate is the failure this fixes.

Open, for whoever picks it up: refuse at set time or accept-and-hold — holding is kinder to a customer who sets the domain before the CNAME. And the expected record needs stating in the customer-facing copy.

Sequenced with #306: same function, same file, separate PRs — this one changes customer-visible behaviour and #306 does not.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions