feat(p/AZURE_PRIVATE_DNS): add DefaultAzureCredential, OIDC auth and error handling fixes - #4847
Closed
matthewmgamble wants to merge 4 commits into
Closed
matthewmgamble wants to merge 4 commits into
matthewmgamble wants to merge 4 commits into
Conversation
- Disable HTTP compression to prevent 403 from Infoblox Apache proxy - Request non-standard return fields for CAA (ca_flag, ca_tag, ca_value) and PTR (name) record types - Remove ttl/use_ttl from NS record queries (unsupported by WAPI) - Remove NS from supportedTypes (requires addresses field that dnscontrol does not provide) - Strip ttl/use_ttl from NS record create/update bodies - Tighten TXT audit: reject empty TXT and strings longer than 255 bytes - Add INFOBLOX integration test profile
- Add provider documentation (documentation/provider/infoblox.md) - Add INFOBLOX to README.md provider table - Add CODEOWNERS entry for providers/infoblox - Add INFOBLOX env vars to pr_integration_tests.yml - Add INFOBLOX to documentation/SUMMARY.md - Update auto-generated files (labeler.yml, goreleaser.yml, index.md) - Reformat profiles.json via generate-all.sh
…andling fixes Port authentication and error handling improvements from AZURE_DNS to AZURE_PRIVATE_DNS so both providers stay in sync: - Support DefaultAzureCredential (default when no ClientID/Secret given) - Support OIDC interactive browser authentication (UseOIDC=true) - Normalize resource group to lowercase for case-insensitive matching - Fix fetchRecordSets to use errors.As instead of type assertion - Wrap client creation errors with fmt.Errorf for better diagnostics - Update documentation with all three auth method examples
Collaborator
|
I think this is based on the InfoBlox branch, not main. We can rebase after that one is merged. |
Collaborator
|
I think this may have been based off of the pre-v5 branch. Please rebase and convert to v5.x convention. See documentation/developer-info/modernizingproviders.md |
Collaborator
|
Closing in favor of #4929 |
TomOnTime
added a commit
that referenced
this pull request
Sep 26, 2026
…ds as AZURE_DNS (#4929) # Issue Azure's "Azure Private DNS" service supports the same authentication methods as Azure's "Azure DNS" service. However the code for DNSControl's `AZURE_PRIVATE_DNS` provider doesn't support the same methods. That is, `AZURE_PRIVATE_DNS` is missing support for # Resolution - Port authentication improvements from `AZURE_DNS` to `AZURE_PRIVATE_DNS` so both providers support the same auth methods: DefaultAzureCredential (default fallback), Client ID + Secret (backward compatible), and OIDC interactive browser login - Normalize resource group name to lowercase for case-insensitive matching (matching `AZURE_DNS` behavior) - Fix `fetchRecordSets()` to use `errors.As` instead of type assertion for proper wrapped error handling - Wrap client creation errors with `fmt.Errorf` for better diagnostics - Update provider documentation with examples for all three auth methods CC @matthewmgamble I've ported your changes to v5. Please confirm this works as I don't have access. CC @cafferata Please review the docs. They should be nearly identical to AZURE_DNS. I ported over the changes from #4847
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
AZURE_DNStoAZURE_PRIVATE_DNSso both providers support the same auth methods: DefaultAzureCredential (default fallback), Client ID + Secret (backward compatible), and OIDC interactive browser loginAZURE_DNSbehavior)fetchRecordSets()to useerrors.Asinstead of type assertion for proper wrapped error handlingfmt.Errorffor better diagnosticsTest plan
go build ./...passesgo vet ./providers/azureprivatedns/...passesgo test ./providers/azureprivatedns/...passesUseOIDC=true