Repository navigation
feat: let providers declare a record identity for duplicate checks - #4883
Conversation
|
Hi there! Thanks for submitting this! I didn't even realize it was a problem. Thank you for reporting it. Let me suggest an easier way to fix this. It might not be better or equivalent. I'm interested in your feedback. What if we added a metadata flag similar to DISABLE_REPEATED_DOMAIN_CHECK, perhaps called DISABLE_DUPLICATE_RECORD_CHECK? Records with that metadata would be exempt from the checkDuplicates and checkCNAMEs checks. The benefit would be that it would not require provider changes. The downside is that it could lead to some false negatives which will later be detected/rejected at Tom |
|
Thanks for the suggestion, and for spelling out the trade-off. I would like to keep the provider-declared identity. The main argument for it is already in this repo. The two testgroups already in Both pass today because the integration path goes through The provider side already declares this identity. For DNSPod the key is measurable. The account exposes a read-only conflict check, Probing existing records against it returns the key as (name, line, type, value), with the line matched by A flag stops at validation. With the same per-line config, the provider's comparable produces the expected CREATEs; replace it with
Cost is close either way. The hook is one optional field on |
Validation runs before the provider has fetched the zone, so the identity function cannot depend on a record set. It takes a single record now, and the tencentdns implementation reads only that record: the line ID, falling back to the line name. Weight is no longer part of it, because the service keys records on name, line, type and value and rejects two records that differ only by weight.
Providers that store per-line records now have a documented hook: what it does, the rule that it must depend only on the record it is given, and what happens when a domain has several providers. The tencentdns page states that duplicate detection uses the key the service uses, and that mixing a line name with a line ID describes the same line twice. Tests cover weight, line names on their own, and the record-only signature.
5469f95 to
9240964
Compare
2a638e6 to
0a31d9f
Compare
Validation now treats a record without line metadata as the default line, so it matches an explicit line ID of 0. The default line also has one name and one ID. The tests describe a generic zone with RFC 5737 addresses, and the provider without an identity function is registered instead of unknown. The provider docs note where validation cannot see the zone.
0a31d9f to
039e2fc
Compare
|
Ok! |
As discussed in #4897, this keeps the table of contents that #4818 added and makes its links work on https://docs.dnscontrol.org next to GitBook's "On this page" navigation. All pages are done in this one pull request, as requested. The TOC no longer starts with an entry for the page title, because GitBook renders the H1 as the page title without an anchor. The links now use the anchors GitBook generates. Besides the two differences mentioned in the issue (periods are kept, and a heading that starts with a number gets an `id-` prefix), GitBook also turns a `/` into a dash and a `&` into `and`: "Don't conditionally add/remove trailing dots" becomes `#dont-conditionally-add-remove-trailing-dots`. I compared every heading of the 35 published pages with the `id` attributes on docs.dnscontrol.org, and all TOC links now match an existing anchor. A few other changes came along: - Step headings use a colon everywhere (`Step 1: Pick a unique id`) instead of a mix of `Step 1.` and `Step 1:`, matching `writing-providers.md` and the "Step 1: Foo" example in `styleguide-doc.md`. A colon is dropped by GitHub and GitBook alike, so these anchors are the same on both sites. - Headings that used ` - ` or `&` now use a colon or "and" (`ci-cd-gitlab.md`, `github-actions.md`, `goreleaser.md`), so their anchors are the same on GitHub and GitBook as well. - The TOC stops at H4. GitBook renders an H5 as bold text without an anchor, so the six numbered steps under "Steps to activate" in `goreleaser.md` couldn't be linked on GitBook anyway. - The TOCs of `debugging-with-dlv.md` (still linking to the old "Debugger" title and missing "Debug `helpers.js`") and `writing-providers.md` (missing "Record identity for providers with per-line records" from #4883) were out of date and are regenerated from the headings. - `modernizingproviders.md` isn't in `SUMMARY.md`, so it isn't published on GitBook. It only loses the entry for the page title and keeps the GitHub anchors. - `provider/index.md` is left alone, because its "Jump to a table" list is generated and its anchors already match. The trade-off is GitHub: 33 of the 288 links on the published pages use a GitBook anchor that GitHub generates differently, so they don't jump to the heading when you read the Markdown on github.com. The VS Code plug-in would also write GitHub anchors and the H1 entry back when it regenerates a TOC, so it's worth limiting it to levels 2 to 4 and checking the anchors of headings with a period, a leading number, a `/` or a `&` after regenerating. Fixes #4897 ## AI-attributie Assisted-by: Claude Code:claude-opus-5-5
I ran into this while moving a geo-routed zone to DNSControl.
DNSPod, Gcore, Huawei Cloud and ClouDNS keep one record per line, so several
records share a name and type. That is how these providers express per-region
answers.
Two checks block those configs before the provider ever sees them.
checkCNAMEsrejects a second CNAME under the same name, so a geo-routed CNAMEset cannot be declared at all.
checkDuplicatescompares name, type and RDATA and never looks at providermetadata, so two records that differ only by line count as duplicates even
though the provider stores them separately.
The
R53_WEIGHTexample in the docs fails the same check, so this is notspecific to any one provider.
The change adds an optional identity function to the provider interface. A
provider that declares one gets its identity text appended to the duplicate
key. A provider that declares nothing keeps today's rules.
Route 53 weighted records and Cloudflare flattened CNAMEs already rely on
hard-coded exceptions to the same checks. A generic hook gives other providers
a supported way in.