Skip to content

feat(p/AZURE_PRIVATE_DNS): Add OIDC support / support same auth methods as AZURE_DNS - #4929

Merged
TomOnTime merged 4 commits into
mainfrom
tlim_azure
Sep 26, 2026
Merged

TomOnTime merged 4 commits into
mainfrom
tlim_azure

Conversation

@TomOnTime

Copy link
Copy Markdown
Collaborator

Issue

Azure's "Azure Private DNS" service supports the same authentication methods as Azure's "Azure DNS" service. However the code for DNSControl's AZURE_PRIVATE_DNS provider doesn't support the same methods. That is, AZURE_PRIVATE_DNS is missing support for

Resolution

  • Port authentication improvements from AZURE_DNS to AZURE_PRIVATE_DNS so both providers support the same auth methods: DefaultAzureCredential (default fallback), Client ID + Secret (backward compatible), and OIDC interactive browser login
  • Normalize resource group name to lowercase for case-insensitive matching (matching AZURE_DNS behavior)
  • Fix fetchRecordSets() to use errors.As instead of type assertion for proper wrapped error handling
  • Wrap client creation errors with fmt.Errorf for better diagnostics
  • Update provider documentation with examples for all three auth methods

CC @matthewmgamble I've ported your changes to v5. Please confirm this works as I don't have access.

CC @cafferata Please review the docs. They should be nearly identical to AZURE_DNS. I ported over the changes from #4847

@TomOnTime TomOnTime changed the title feat(p/AZURE_PRIVATE_DNS): Add OIDC support / support same auth methds as AZURE_DNS feat(p/AZURE_PRIVATE_DNS): Add OIDC support / support same auth methods as AZURE_DNS Sep 22, 2026

@cafferata cafferata left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @TomOnTime. I compared the AZURE_PRIVATE_DNS preview with the AZURE_DNS page side by side, and apart from the naming the sections now match. I left one inline comment.

The other way around, the AZURE_DNS page has drifted a bit from the code this pull request ports: its Caveats still say "The ResourceGroup is case sensitive." although AZURE_DNS lowercases it as well, its Activation section only mentions client credentials, and there's a stray + before the second "You can also use environment variables:". Happy to pick that up in a separate pull request so this one stays focused.

Comment thread documentation/provider/azureprivatedns.md Outdated
@TomOnTime
TomOnTime merged commit b719bca into main Sep 26, 2026
40 checks passed
@TomOnTime
TomOnTime deleted the tlim_azure branch September 26, 2026 14:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Development

Successfully merging this pull request may close these issues.

2 participants