Conversation
scotwells
force-pushed
the
feat/wildcard-certificates
branch
from
October 2, 2026 22:13
f3e60c6 to
1104b62
Compare
scotwells
force-pushed
the
feat/alb-plugin-wildcards
branch
from
October 2, 2026 22:13
8659581 to
18ed21b
Compare
The plugin shared the operator's hostname check, so it refused wildcards before the platform could judge them, and describe gave no way to see the DNS records a hostname still waits on. hostname add now accepts a single leading wildcard label, and describe prints the records still to publish from the load balancer's status. Key changes: - accept "*." hostnames locally; the platform decides whether they are enabled and proven - print each refused hostname's reason beneath it - list missing user records once each, with the certificate CNAME, and platform records still waiting on Datum DNS apart - point the "DNS not delegated" hint at the certificate record, so the certificate can issue at the provider that serves the domain today - document wildcards and the records list
scotwells
force-pushed
the
feat/alb-plugin-wildcards
branch
from
October 2, 2026 23:35
18ed21b to
d5e98cc
Compare
scotwells
force-pushed
the
feat/wildcard-certificates
branch
from
October 2, 2026 23:35
1104b62 to
83190b1
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The
datumctl albplugin checks hostnames with the operator's own rules before sending them, so it refused every wildcard, anddescribegave no way to see which DNS records a hostname still waits on.The plugin now accepts a hostname with one leading wildcard label and leaves the platform to decide whether wildcards are enabled and proven.
describeprints the records still to publish from the load balancer's status, including the certificate record, and its "DNS not delegated" hint now points at that certificate record.This is stacked on #531.
API
No API change. What a user sees:
A wildcard the platform refused shows the reason beneath it, and the ownership record it needs:
The plugin reads the hostname status list and nothing else, so it never depends on how certificates are named or stored.
Local validation errors users hit:
'*.s3.example.com''*.*.example.com'or'foo.*.example.com''*.datumproxy.net'The plugin docs gain a short wildcards section.
Test plan
hostname addaccepts a single-label wildcard and refuses a multi-label onedescribeon a load balancer with a wildcard prints the certificate CNAMERelated to datum-cloud/enhancements#913