Skip to content

feat(p/AZURE_PRIVATE_DNS): add DefaultAzureCredential, OIDC auth and error handling fixes - #4847

Closed
matthewmgamble wants to merge 4 commits into
DNSControl:mainfrom
matthewmgamble:azureprivatedns-auth-improvements
Closed

matthewmgamble wants to merge 4 commits into
DNSControl:mainfrom
matthewmgamble:azureprivatedns-auth-improvements

Conversation

@matthewmgamble

Copy link
Copy Markdown
Contributor
  • Port authentication improvements from AZURE_DNS to AZURE_PRIVATE_DNS so both providers support the same auth methods: DefaultAzureCredential (default fallback), Client ID + Secret (backward compatible), and OIDC interactive browser login
  • Normalize resource group name to lowercase for case-insensitive matching (matching AZURE_DNS behavior)
  • Fix fetchRecordSets() to use errors.As instead of type assertion for proper wrapped error handling
  • Wrap client creation errors with fmt.Errorf for better diagnostics
  • Update provider documentation with examples for all three auth methods

Test plan

  • go build ./... passes
  • go vet ./providers/azureprivatedns/... passes
  • go test ./providers/azureprivatedns/... passes
  • Verify DefaultAzureCredential auth works with managed identity or Azure CLI
  • Verify Client ID + Secret auth still works (backward compatibility)
  • Verify OIDC interactive browser auth works with UseOIDC=true

- Disable HTTP compression to prevent 403 from Infoblox Apache proxy
- Request non-standard return fields for CAA (ca_flag, ca_tag, ca_value)
  and PTR (name) record types
- Remove ttl/use_ttl from NS record queries (unsupported by WAPI)
- Remove NS from supportedTypes (requires addresses field that
  dnscontrol does not provide)
- Strip ttl/use_ttl from NS record create/update bodies
- Tighten TXT audit: reject empty TXT and strings longer than 255 bytes
- Add INFOBLOX integration test profile
- Add provider documentation (documentation/provider/infoblox.md)
- Add INFOBLOX to README.md provider table
- Add CODEOWNERS entry for providers/infoblox
- Add INFOBLOX env vars to pr_integration_tests.yml
- Add INFOBLOX to documentation/SUMMARY.md
- Update auto-generated files (labeler.yml, goreleaser.yml, index.md)
- Reformat profiles.json via generate-all.sh
…andling fixes

Port authentication and error handling improvements from AZURE_DNS to
AZURE_PRIVATE_DNS so both providers stay in sync:

- Support DefaultAzureCredential (default when no ClientID/Secret given)
- Support OIDC interactive browser authentication (UseOIDC=true)
- Normalize resource group to lowercase for case-insensitive matching
- Fix fetchRecordSets to use errors.As instead of type assertion
- Wrap client creation errors with fmt.Errorf for better diagnostics
- Update documentation with all three auth method examples
@TomOnTime

Copy link
Copy Markdown
Collaborator

I think this is based on the InfoBlox branch, not main. We can rebase after that one is merged.

@TomOnTime

Copy link
Copy Markdown
Collaborator

I think this may have been based off of the pre-v5 branch. Please rebase and convert to v5.x convention. See documentation/developer-info/modernizingproviders.md

@cafferata cafferata changed the title AZURE_PRIVATE_DNS: Add DefaultAzureCredential, OIDC auth, and error handling fixes feat(p/AZURE_PRIVATE_DNS): add DefaultAzureCredential, OIDC auth and error handling fixes Sep 19, 2026
@TomOnTime

Copy link
Copy Markdown
Collaborator

Closing in favor of #4929

@TomOnTime TomOnTime closed this Sep 22, 2026
TomOnTime added a commit that referenced this pull request Sep 26, 2026
…ds as AZURE_DNS (#4929)

# Issue

Azure's "Azure Private DNS" service supports the same authentication
methods as Azure's "Azure DNS" service. However the code for
DNSControl's `AZURE_PRIVATE_DNS` provider doesn't support the same
methods. That is, `AZURE_PRIVATE_DNS` is missing support for

# Resolution

- Port authentication improvements from `AZURE_DNS` to
`AZURE_PRIVATE_DNS` so both providers support the same auth methods:
DefaultAzureCredential (default fallback), Client ID + Secret (backward
compatible), and OIDC interactive browser login
- Normalize resource group name to lowercase for case-insensitive
matching (matching `AZURE_DNS` behavior)
- Fix `fetchRecordSets()` to use `errors.As` instead of type assertion
for proper wrapped error handling
- Wrap client creation errors with `fmt.Errorf` for better diagnostics
- Update provider documentation with examples for all three auth methods


CC @matthewmgamble I've ported your changes to v5. Please confirm this
works as I don't have access.

CC @cafferata Please review the docs. They should be nearly identical to
AZURE_DNS. I ported over the changes from
#4847
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Development

Successfully merging this pull request may close these issues.

2 participants