Skip to content

feat: Stage 5: Add SupportedTypes and exhaustive provider validation - #4967

Open
TomOnTime wants to merge 3 commits into
tlim_stage4_registryfrom
tlim_stage5_types
Open

TomOnTime wants to merge 3 commits into
tlim_stage4_registryfrom
tlim_stage5_types

Conversation

@TomOnTime

@TomOnTime TomOnTime commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

Instead of registering each type a provider supports, with this change the types are reported as a list:

Other capabilities become individual fields.

This data is converted so that legacy code still works. Legacy code will be converted in the future.

An example tells the story better:

providers/foo/fooPrivateDnsProvider.go
@@ -131,26 +131,21 @@ func init() {
                       },
               },
               Maintainer: "@TomOnTime",
               SupportedTypes: []string{
                       "Default",            // The basic 8: A, AAAA, CAA, CNAME, MX, NS, SRV, TXT 
                       "PTR",
                       "CAA:Unimplemented",  // The provider supports it, but we haven't written the code
                       "NS:Cannot",          // NOT supported by the provider.
               },
               CanConcur:              providers.Can(),
               CanAutoDNSSEC:          providers.Cannot(),
               DocDualHost:            providers.Cannot("Private zones can not change NS records"),
               DocOfficiallySupported: providers.Can(),

CC @cafferata this is the base PR. Converting all the other providers is in #4968

Details...

Providers can now opt into an exhaustive Definition.SupportedTypes declaration. Default contains A, AAAA, CAA, CNAME, MX, NS, SRV, and TXT. For example, []string{"Default", "NS:Cannot"} excludes NS from that baseline; []string{"RFC", "CAA:Cannot"} allows ordinary catalog records except CAA; []string{"*"} also allows pseudo-types. Existing legacy providers keep their previous validation coverage.

This implements Stage 5 on top of #4966 and targets tlim_stage4_registry.

  • Resolve defaults, patterns, statuses, legacy exceptions, and conflicts independently of declaration order. Finalize against the complete record catalog and retain compiled selectors for later registrations.
  • Validate original types before transforms and resulting types afterwards, preserve child-only DS support and provider auditing, and derive legacy capabilities from one shared mapping.
  • Migrate BIND as the sole production pilot. Its wildcard accepts pseudo-types without legacy ownership markers and writes them verbatim. Tests cover parsing, normalization, writing, reading, and a second correction with no changes.
  • Document the declaration syntax and update BIND's generated ALIAS capability entries. Broad provider adoption and removal of custom-record registration remain in Stage 6.

Validation passed: go test ./...; bin/generate-all.sh (including go fix, golangci-lint with 0 issues, and staticcheck); git diff --check. The initial Stage 5 implementation also passed go test -race -count=2 ./pkg/providers ./pkg/privatetypes ./pkg/normalize ./providers/bind. No live provider integration profile was selected.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Development

Successfully merging this pull request may close these issues.

1 participant