Skip to content

feat: Reject ALIAS records at wildcard names - #227

Merged
scotwells merged 1 commit into
mainfrom
feat/reject-wildcard-alias
Oct 7, 2026
Merged

scotwells merged 1 commit into
mainfrom
feat/reject-wildcard-alias

Conversation

@scotwells

Copy link
Copy Markdown
Contributor

Summary

A wildcard ALIAS record used to be accepted and published but never resolved, because the DNS server only expands an ALIAS when the query name matches the record exactly. It is now rejected at write time with a message pointing to CNAME, which works at wildcards.

User experience

Before: this was accepted, and queries under app never resolved.

apiVersion: dns.networking.miloapis.com/v1alpha1
kind: DNSRecordSet
metadata:
  name: wildcard-app
spec:
  dnsZoneRef:
    name: my-zone
  recordType: ALIAS
  records:
    - name: "*.app"
      alias:
        content: target.example.net.

After: the same object is rejected on create and update.

The DNSRecordSet "wildcard-app" is invalid: spec.records[0].name: Invalid value: "*.app": ALIAS records cannot be used at wildcard names; use a CNAME for "*.app"

Unchanged: CNAME, A and AAAA at wildcards, and ALIAS at the apex (@) or an exact name like www. A wildcard ALIAS that is already stored stays editable on updates that do not add it; only newly added wildcard ALIAS names are refused.

Test plan

  • ALIAS at *, *.app and an FQDN wildcard is rejected on create
  • Adding a wildcard ALIAS, or changing a wildcard CNAME to ALIAS, is rejected on update
  • CNAME, A and AAAA at wildcards, and ALIAS at @ and www, are accepted
  • make lint clean; webhook tests pass (the pdns integration tests need Docker and were not run)

Fixes #226

PowerDNS expands an ALIAS only when the query name equals the record
owner exactly, so an ALIAS at "*" or "*.app" was accepted and published
but never resolved.

Key changes:
- Refuse an ALIAS record whose name has "*" as its first label on
  create and update, with a message pointing to CNAME
- Keep a wildcard ALIAS already stored editable when an update does not
  add it, matching how held owner names are treated
- Note the rule in the agent record-type guidance
@scotwells
scotwells marked this pull request as ready for review October 7, 2026 19:10
@scotwells
scotwells requested a review from a team as a code owner October 7, 2026 19:10
@scotwells
scotwells merged commit 4513512 into main Oct 7, 2026
12 checks passed
@scotwells
scotwells deleted the feat/reject-wildcard-alias branch October 7, 2026 19:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Reject ALIAS records at wildcard names

2 participants