Skip to content

atenet/dns: publish the router's IPv6 ClusterIP as an AAAA - #938

Open
Yuan Gao (ygao-g) wants to merge 3 commits into
agent-substrate:mainfrom
ygao-g:atenet-dns-aaaa
Open

atenet/dns: publish the router's IPv6 ClusterIP as an AAAA#938
Yuan Gao (ygao-g) wants to merge 3 commits into
agent-substrate:mainfrom
ygao-g:atenet-dns-aaaa

Conversation

@ygao-g

@ygao-g Yuan Gao (ygao-g) commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

Depends on #874, whose commit appears in this diff until it merges.

Actor names have no IPv6 address. #874 made the zone answer AAAA correctly but emptily; this gives it something to answer with. Every actor name resolves to the same address — the atenet-router ClusterIP, with per-actor demux happening at Envoy on the Host header — so publishing AAAA means publishing the router's v6 ClusterIP. The zone now publishes an address record per family the router has a ClusterIP in.

It also fixes a hard failure on IPv6-only clusters, where the router's only ClusterIP is a v6 address and the zone published it as an IN A record. Every A query for an actor name SERVFAILs there today, for every client, not just musl.

Ordering against #911. Prefer landing after it, but the dependency is soft: without #911 the router Service is SingleStack, so no dual-stack cluster has a v6 ClusterIP to publish and the rendered zone is unchanged. The case to avoid is #911 being split — a dual-stack Service without the :: listener publishes an AAAA nothing is bound to, and Happy Eyeballs takes the working IPv4 path down with it.

Also stops the Corefile generation timestamp from being recomputed per render, which was reloading CoreDNS on every reconcile tick.

Testing. Unit tests compare the whole rendered zone against a golden for each family combination, plus a manual pass against the pinned coredns/coredns:1.11.1. TestActorDNSAAAA is the e2e counterpart and stays out of this PR — it needs the dual-stack e2e scaffolding, the same carve-out #874 makes for TestActorDNSZone.

Part of #246.

Before, the actor zone answered A queries and failed everything else -- AAAA
for a valid actor, and any name in the zone that is not an actor. A failure
reads as a temporary error rather than an answer, so clients retry it and then
give up on the name; Alpine actors could not resolve each other at all, even on
an IPv4-only cluster. After, those queries return a correct empty answer, and
one that resolvers can cache.

Unit tests pin the rendered zone. The before/after behaviour was verified
against the pinned coredns/coredns:1.11.1, where an Alpine getent for an actor
name goes from timing out to answering immediately.
Splits a Service's cluster IPs into its IPv4 and IPv6 entries, returning "" for
a family the Service has no address in. No behaviour change on its own --
nothing calls it until the next commit. Shared rather than package-local
because the DNS controller and the e2e dual-stack tests both have to agree on
what "no address in that family" means: a Service with no ipFamilyPolicy is
SingleStack, so that is the steady state everywhere, not an error.

Unit tests cover single- and dual-stack Services and the unallocated and
malformed cases.
Before, an actor name never resolved over IPv6. The zone published only the
router's primary cluster IP and always as an A record, whatever family it was:
on a dual-stack cluster the v6 address went unpublished, and on an IPv6-only
cluster the record was malformed, so every A query for an actor name failed.
After, the zone publishes an address record per family the router has an
address in, and answers empty for a family it has none in. Also stops
recomputing the Corefile generation timestamp per render, which was reloading
CoreDNS on every reconcile tick.

Unit tests pin the rendered zone for each family combination. The behaviour was
verified against the pinned coredns/coredns:1.11.1.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant