Technitium ExternalDNS Implementation Plan¶
⚠️ SUPERSEDED / HISTORICAL. This plan describes the original
internal.vanillax.metest zone, which has been retired. Production uses split DNS on real names undervanillax.me(nointernal.prefix). For the live design, cutover order, and known pitfalls seedocs/domains/networking/technitium-vanillax-me-migration.md. Kept only as a dated record of how the test instance was built.For agentic workers: REQUIRED SUB-SKILL: Use superpowers:subagent-driven-development (recommended) or superpowers:executing-plans to implement this plan task-by-task. Steps use checkbox (
- [ ]) syntax for tracking.
Goal: Add an isolated RFC2136 ExternalDNS instance and test Gateway for internal.vanillax.me.
Architecture: Render a second release of the repository's existing ExternalDNS Helm chart inside the current Argo CD application. Use a dedicated Cilium Gateway at 192.168.10.52, label-filter route discovery, and reuse the existing Cloudflare DNS-01 ClusterIssuer for TLS.
Tech Stack: Argo CD, Kustomize, Helm, ExternalDNS, External Secrets, 1Password Connect, Cilium Gateway API, cert-manager, Technitium RFC2136
Task 1: Add The Technitium ExternalDNS Release¶
Files:
- Create: infrastructure/controllers/external-dns/technitium-external-secret.yaml
- Create: infrastructure/controllers/external-dns/values-technitium.yaml
- Modify: infrastructure/controllers/external-dns/kustomization.yaml
- Add an ExternalSecret mapping
external-dns-technitium/tsig-secretto the namespaced Kubernetes Secret. - Add Helm values for RFC2136, Gateway HTTPRoute discovery, domain filtering, TXT ownership, and safe upsert-only policy.
- Add the resource and second Helm release to the existing Kustomization.
- Render with
kubectl kustomize infrastructure/controllers/external-dns --enable-helm.
Task 2: Add The Isolated Gateway¶
Files:
- Create: infrastructure/networking/gateway/gateway-internal-technitium.yaml
- Modify: infrastructure/networking/gateway/kustomization.yaml
- Add a Cilium Gateway pinned to
192.168.10.52. - Add HTTP and HTTPS listeners for
*.internal.vanillax.me. - Reference
cert-internal-vanillaxso cert-manager creates the wildcard certificate. - Add the Gateway to the Kustomization and render it.
Task 3: Document Operation And IP Ownership¶
Files:
- Create: infrastructure/controllers/external-dns/README.md
- Modify: infrastructure/networking/cilium/ip-pool.yaml
- Modify: infrastructure/networking/README.md
- Document the Technitium endpoint, zone, 1Password reference, safe policy, route labels, and
digchecks. - Reserve
192.168.10.52in the IP pool comments and networking assignment table.
Task 4: Validate The GitOps Output¶
Files: - Test: rendered manifests from both changed Kustomizations
- Run
./scripts/validate-argocd-apps.sh. - Render both changed Kustomizations with Helm enabled.
- Assert the rendered Deployment has the expected name, arguments, and Secret environment reference.
- Assert the existing Cloudflare Deployment arguments remain unchanged.
- Run
kubectl apply --dry-run=clienton the rendered manifests. - Review
git diff --checkand the final diff for secret leakage.