Allow root admin to configure DNS servers on behalf of a specific user/domain and support project-scoped DNS servers
- Langage dominant
- Java
- Étoiles
- 3.1k
- Forks
- 1.4k
- Merge moyen
- 6 j 19 h
- PR mergées (30 j)
- 32
Description
### The required feature described as a wish
Currently, a DNS server can only be set up for the calling account/domain, there is no way for a root admin to configure one on behalf of a different account or domain, and no way for a DNS server to belong to a project.
As a root admin, I would like to be able to:
1. Set up a DNS server on behalf of a specific user/account
2. Set up a DNS server on behalf of a specific domain
3. Attach a DNS server to a project
Additional constraint:
4. If a DNS server was set up by root admin on behalf of a user/domain, that user/domain should not be able to modify its URL themselves. Only root admin (or whoever provisioned it) should be able to change it.
Motivation:
Asks 1 and 2 are primarily driven by the recent restriction that only root admin can configure a DNS server on a private/internal (RFC1918) address, domain admins and regular users can no longer do so directly (see [PR #13821](https://github.com/apache/cloudstack/pull/13821/commits/1545adde35dd68a90291687fc3f7cec23b1e13f6)). Without a way for root admin to provision such a server on behalf of another account/domain, that use case is lost entirely for non-root-admin users.
Ask 3 (project support) wasn't part of the initial scope for this feature. It's being tracked here as a follow-up enhancement rather than a gap in the original design.
Ask 4 follows directly from 1 and 2: if the owning user/domain could freely change the URL afterward, they could redirect an admin-provisioned DNS server anywhere they like, defeating the purpose of restricting private-address setup to root admin in the first place.
Guide de contribution
Ouvrir le guide de contribution
Piste de recherche
Commencez par examiner le flux de configuration existant du serveur DNS et la PR #13821, puis retracez la manière dont la propriété des comptes, domaines, projets et administrateurs racine est représentée. La tâche est considérée comme terminée lorsque les administrateurs racine peuvent provisionner des serveurs DNS pour des utilisateurs, des domaines ou des projets, tandis que les utilisateurs et domaines provisionnés ne peuvent pas modifier leurs URLs ; les règles de portée et d’autorisation doivent être couvertes par des tests appropriés.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- java
- Domaine
- authorization, backend-api-design, cloud, networking
- Type d'issue
- Fonctionnalité
- Difficulté
- 5/5
- Temps estimé
- Plus d'une semaine
- Activité
- Active
- Clarté
- Plutôt claire
- Accessibilité débutants
- 38/100