Skip to content

feat: Show the DNS records still to publish in alb describe - #532

Draft
scotwells wants to merge 1 commit into
feat/wildcard-certificatesfrom
feat/alb-plugin-wildcards
Draft

scotwells wants to merge 1 commit into
feat/wildcard-certificatesfrom
feat/alb-plugin-wildcards

Conversation

@scotwells

@scotwells scotwells commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The datumctl alb plugin checks hostnames with the operator's own rules before sending them, so it refused every wildcard, and describe gave no way to see which DNS records a hostname still waits on.

The plugin now accepts a hostname with one leading wildcard label and leaves the platform to decide whether wildcards are enabled and proven.

describe prints the records still to publish from the load balancer's status, including the certificate record, and its "DNS not delegated" hint now points at that certificate record.

This is stacked on #531.

API

No API change. What a user sees:

$ datumctl alb hostname add s3 '*.s3.example.com'
Hostname "*.s3.example.com" attached on "s3".

$ datumctl alb describe s3
...
Custom hostnames:
  *.s3.example.com  available=True  dns=False  cert=False
DNS records to publish:
  NAME                             TYPE    CONTENT                            PURPOSE
  *.s3.example.com                 CNAME   ruth-fourth-hrkgk.datumproxy.net   Routing
  _acme-challenge.s3.example.com   CNAME   k3f9q2x7.acme-dns.example.net      Certificate
DNS not delegated: Datum DNS does not serve *.s3.example.com yet. Publish the certificate record _acme-challenge.s3.example.com at the DNS provider that does serve it, so the certificate issues before traffic moves.

A wildcard the platform refused shows the reason beneath it, and the ownership record it needs:

Custom hostnames:
  *.s3.example.com  available=—  dns=—  cert=False
    The wildcard "*.s3.example.com" needs DNS proof that you control s3.example.com or a parent domain. ...
DNS records to publish:
  NAME                                   TYPE    CONTENT                                PURPOSE
  *.s3.example.com                       CNAME   ruth-fourth-hrkgk.datumproxy.net       Routing
  datum-custom-hostname.s3.example.com   TXT     7c1e0d52-3b8f-4a51-a0f6-2f4b6c9d8e11   Ownership

The plugin reads the hostname status list and nothing else, so it never depends on how certificates are named or stored.

Record state Shown as
Missing, published by the user a row under "DNS records to publish", each record once
Missing, published by the platform a "Waiting on Datum DNS" line
Present not shown

Local validation errors users hit:

Input Result
'*.s3.example.com' sent to the platform
'*.*.example.com' or 'foo.*.example.com' refused locally as not a valid hostname
'*.datumproxy.net' sent, and refused by the platform

The plugin docs gain a short wildcards section.

Test plan

  • Unit tests list missing user records once each, keep platform records apart, and point the hint at the certificate record
  • hostname add accepts a single-label wildcard and refuses a multi-label one
  • Build, vet, lint and the full suite pass locally and in CI
  • Against staging, describe on a load balancer with a wildcard prints the certificate CNAME

Related to datum-cloud/enhancements#913

@scotwells
scotwells force-pushed the feat/wildcard-certificates branch from f3e60c6 to 1104b62 Compare October 2, 2026 22:13
@scotwells
scotwells force-pushed the feat/alb-plugin-wildcards branch from 8659581 to 18ed21b Compare October 2, 2026 22:13
The plugin shared the operator's hostname check, so it refused wildcards
before the platform could judge them, and describe gave no way to see the
DNS records a hostname still waits on. hostname add now accepts a single
leading wildcard label, and describe prints the records still to publish
from the load balancer's status.

Key changes:
- accept "*." hostnames locally; the platform decides whether they are
  enabled and proven
- print each refused hostname's reason beneath it
- list missing user records once each, with the certificate CNAME, and
  platform records still waiting on Datum DNS apart
- point the "DNS not delegated" hint at the certificate record, so the
  certificate can issue at the provider that serves the domain today
- document wildcards and the records list
@scotwells
scotwells force-pushed the feat/alb-plugin-wildcards branch from 18ed21b to d5e98cc Compare October 2, 2026 23:35
@scotwells
scotwells force-pushed the feat/wildcard-certificates branch from 1104b62 to 83190b1 Compare October 2, 2026 23:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant