Skip to content

feat: allow cross projects zone access - #85

Merged
frittentheke merged 3 commits into
inovex:mainfrom
abhijith-darshan:feat/cross-project-zones
Sep 7, 2026
Merged

frittentheke merged 3 commits into
inovex:mainfrom
abhijith-darshan:feat/cross-project-zones

Conversation

@abhijith-darshan

Copy link
Copy Markdown
Contributor

closes #83

@abhijith-darshan
abhijith-darshan force-pushed the feat/cross-project-zones branch from 0c132c0 to 19ab4a9 Compare May 7, 2026 11:49
@abhijith-darshan abhijith-darshan changed the title (chore): allow cross projects zone access feat: allow cross projects zone access May 27, 2026
@abhijith-darshan
abhijith-darshan force-pushed the feat/cross-project-zones branch 2 times, most recently from b6d64cd to 5d42cc8 Compare May 27, 2026 11:41
@frittentheke
frittentheke force-pushed the feat/cross-project-zones branch from 5d42cc8 to 4c22d39 Compare June 7, 2026 10:37
@abhijith-darshan
abhijith-darshan force-pushed the feat/cross-project-zones branch from 4c22d39 to 33e5f25 Compare June 17, 2026 14:42
@abhijith-darshan
abhijith-darshan force-pushed the feat/cross-project-zones branch 2 times, most recently from 1f55541 to 1b7a3e2 Compare July 11, 2026 21:27

@frittentheke frittentheke left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @abhijith-darshan for keeping at this and especially for going the extra mile to implement this in Gophercloud, the right place!

This chance looks good so far.

Since this s feature that needs integration testing, would you mind creating a devstack test for it? I know the current integration testing at https://github.com/inovex/external-dns-openstack-webhook/blob/main/.github/workflows/devstack.yml#L72-L109 is quite simple, but we already have devstack running ... it's just about marking use of it to ensure things work as they should with later changes.

Comment thread cmd/webhook/main.go Outdated
@abhijith-darshan
abhijith-darshan force-pushed the feat/cross-project-zones branch 3 times, most recently from 3dce28f to 58cf282 Compare July 14, 2026 19:43
@abhijith-darshan

abhijith-darshan commented Jul 14, 2026 •

Copy link
Copy Markdown
Contributor Author

Thanks @abhijith-darshan for keeping at this and especially for going the extra mile to implement this in Gophercloud, the right place!

This chance looks good so far.

Since this s feature that needs integration testing, would you mind creating a devstack test for it? I know the current integration testing at https://github.com/inovex/external-dns-openstack-webhook/blob/main/.github/workflows/devstack.yml#L72-L109 is quite simple, but we already have devstack running ... it's just about marking use of it to ensure things work as they should with later changes.

I can try. Should this be a separate workflow or extend the existing one with a separate job or add additional step?

@abhijith-darshan

Copy link
Copy Markdown
Contributor Author

@frittentheke how does this look?

added webhook server and status server addr flags so that they can be configurable. Otherwise in the test we would have to kill existing running webhook.

Also noticed the designate-worker fix was removed by you in the past - 3b52507

we just needed the abs path after [DEFAULT] and looks like the test time also reduces by 8 - 9 mins approx.

@frittentheke

frittentheke commented Aug 4, 2026 •

Copy link
Copy Markdown
Collaborator

Sorry about the delay @abhijith-darshan ! I shall try to look into this soon.
Do you mind rebasing this once more?

@Knalltuete5000 Knalltuete5000 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor details for the devstack but LGT

Comment thread .github/workflows/devstack.yml Outdated
Comment thread .github/workflows/devstack.yml Outdated
@abhijith-darshan

Copy link
Copy Markdown
Contributor Author

Sorry about the delay @abhijith-darshan ! I shall try to look into this soon. Do you mind rebasing this once more?

Done ... @frittentheke please review

@abhijith-darshan

abhijith-darshan commented Aug 21, 2026 •

Copy link
Copy Markdown
Contributor Author

@frittentheke we now have an official release of gophercloud/v2.14.0 🎉

could you please review? We need to migrate our fleet from Ingress to Gateway API 😭

@abhijith-darshan

Copy link
Copy Markdown
Contributor Author

@frittentheke Could you please review?

@frittentheke

Copy link
Copy Markdown
Collaborator

@abhijith-darshan I was on vacation and we should get this review done and merged this week.
Could you please rebase your MR once more?

@abhijith-darshan

Copy link
Copy Markdown
Contributor Author

@abhijith-darshan I was on vacation and we should get this review done and merged this week. Could you please rebase your MR once more?

Done

Comment thread .github/workflows/devstack.yml Outdated
Comment thread .github/workflows/devstack.yml
Comment thread cmd/webhook/main.go
Comment thread .github/workflows/devstack.yml Outdated
Comment thread .github/workflows/devstack.yml Outdated

@frittentheke frittentheke left a comment •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @abhijith-darshan for all your patenience.
The PR looks good to me now as well!

I'd just like to ask your to squash the commits a little:

  1. The revert of the root helper fix (0ef0a71) should be a standalone commit (just blame me for removing it :-) )
  2. Your feature including all tests as a single commit
  3. The addition of configurable listeners in 8fcc57c

This reduces the number of commits from 13 to just 3.
If there are no changes to the syntax, I'll hit merge and cut a release.

designate-rootwrap lives in the devstack venv which is not in sudo's
secure_path, causing rndc addzone to fail and zones to stay PENDING.
Insert the absolute venv path as root_helper in designate.conf.

Signed-off-by: abhijith-darshan <abhijith.ravindra@sap.com>
Add --all-projects flag to the webhook which sets X-Auth-All-Projects
on every Designate API request, enabling an admin user to manage DNS
records across projects it does not own.

- ForEachZone, ForEachRecordSet, CreateRecordSet, UpdateRecordSet all
  pass AllProjects through to gophercloud opts
- DeleteRecordSet uses recordsets.DeleteWithOpts (gophercloud v2.14.0)
  so the header is sent on deletes as well
- Bump gophercloud/v2 to v2.14.0 which includes upstream PR #3844
- Add devstack CI test: zone owned by alt_demo project, webhook running
  as admin (not a member of alt_demo) creates records via --all-projects

Signed-off-by: abhijith-darshan <abhijith.ravindra@sap.com>
Add --webhook-server-address (default 127.0.0.1:8888) and
--status-server-address (default 0.0.0.0:8080) flags so operators
can bind the servers to custom addresses without env vars.

Signed-off-by: abhijith-darshan <abhijith.ravindra@sap.com>
@frittentheke
frittentheke merged commit d409857 into inovex:main Sep 7, 2026
1 check passed
@abhijith-darshan
abhijith-darshan deleted the feat/cross-project-zones branch September 7, 2026 09:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add --all-projects flag to support cross-project zone management via X-Auth-All-Projects header

3 participants