Conversation
4 tasks
The edge prefers an exact hostname over a wildcard, so if another project could claim bucket.s3.example.com under someone's *.s3.example.com it would take that traffic. Hostname claims now cover subtrees behind the certificate service flag: a wildcard reserves every name beneath it, at any depth, for its project. Key changes: - refuse a claim beneath another project's wildcard, and a wildcard while another project holds a name beneath it; the refusal names the hostnames, never the project, and says reclaiming is not supported yet - name wildcard claims from a hash of their base, with the hostname in their data, since a ConfigMap name cannot hold "*"; the name has no dot so it never meets a custom hostname's claim - find wildcards above a name with one cached GET per parent domain, and names beneath a wildcard with a cache index on every parent domain, so no lookup scans the claim namespace - re-check held claims every reconcile and keep the older of two that raced, so a cache-lag race settles the same way on both sides - carry the refusal onto the hostname's Available condition
scotwells
force-pushed
the
feat/wildcard-subtree-claims
branch
from
October 2, 2026 23:35
0eb1775 to
66f7c49
Compare
scotwells
force-pushed
the
feat/wildcard-dns-records
branch
from
October 2, 2026 23:35
b08f52f to
2478d6d
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The edge prefers an exact hostname over a wildcard, so a project that could claim one name beneath another project's wildcard would take that name's traffic.
Hostname claims now cover whole subtrees, so a wildcard reserves every name beneath it, at any depth, for the project that holds it.
A later claim beneath another project's wildcard is refused, and so is a wildcard while another project holds a name beneath it, with the refusal naming those hostnames but never the project.
This is behind the certificate service setting, which is off by default, and is stacked on #528.
API
No new fields. A refused hostname reports the reason it already uses for a taken hostname, with a message that says what overlaps.
bucket.s3.example.com*.s3.example.coma.b.s3.example.com*.s3.example.com*.s3.example.comphotos.s3.example.com*.s3.example.com*.example.comor*.b.s3.example.com*.s3.example.coms3.example.comNaming hostnames tells the requester which names exist beneath a domain they have already proven they own. Project identities are never shown.
Reclaiming a name from another project is out of scope. Hosted zone claims (datum-cloud/enhancements#917) will define that override for hostnames and zones together, so the refusal says it is not supported yet.
Claims stay one record per hostname on the platform control plane. A wildcard's record is named from a hash of its base, because a record name cannot hold an asterisk, and that name has no dot, so it never collides with an exact hostname's record.
Finding a wildcard above a name is one cached lookup per parent domain. Finding names beneath a wildcard uses an in-memory index of every parent domain of every claim, so no request scans the claims. The index exists only with the setting on.
Claims are rechecked on every pass. When two overlapping claims race past each other's cache, the older one keeps its name and the newer one is released.
Test plan
Related to datum-cloud/enhancements#913