apache / apache/cloudstack

Allow root admin to configure DNS servers on behalf of a specific user/domain and support project-scoped DNS servers

Ouverte
#13,911 1 commentaire 0 réactions 0 personnes assignées Voir sur GitHub
component:networking type:new-feature
Langage dominant
Java
Étoiles
3.1k
Forks
1.4k
Merge moyen
6 j 19 h
PR mergées (30 j)
32

Description

### The required feature described as a wish

Currently, a DNS server can only be set up for the calling account/domain, there is no way for a root admin to configure one on behalf of a different account or domain, and no way for a DNS server to belong to a project.

As a root admin, I would like to be able to:

1. Set up a DNS server on behalf of a specific user/account
2. Set up a DNS server on behalf of a specific domain
3. Attach a DNS server to a project

Additional constraint:

4. If a DNS server was set up by root admin on behalf of a user/domain, that user/domain should not be able to modify its URL themselves. Only root admin (or whoever provisioned it) should be able to change it.

Motivation:

Asks 1 and 2 are primarily driven by the recent restriction that only root admin can configure a DNS server on a private/internal (RFC1918) address, domain admins and regular users can no longer do so directly (see [PR #13821](https://github.com/apache/cloudstack/pull/13821/commits/1545adde35dd68a90291687fc3f7cec23b1e13f6)). Without a way for root admin to provision such a server on behalf of another account/domain, that use case is lost entirely for non-root-admin users.

Ask 3 (project support) wasn't part of the initial scope for this feature. It's being tracked here as a follow-up enhancement rather than a gap in the original design.

Ask 4 follows directly from 1 and 2: if the owning user/domain could freely change the URL afterward, they could redirect an admin-provisioned DNS server anywhere they like, defeating the purpose of restricting private-address setup to root admin in the first place.

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Commencez par examiner le flux de configuration existant du serveur DNS et la PR #13821, puis retracez la manière dont la propriété des comptes, domaines, projets et administrateurs racine est représentée. La tâche est considérée comme terminée lorsque les administrateurs racine peuvent provisionner des serveurs DNS pour des utilisateurs, des domaines ou des projets, tandis que les utilisateurs et domaines provisionnés ne peuvent pas modifier leurs URLs ; les règles de portée et d’autorisation doivent être couvertes par des tests appropriés.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
java
Domaine
authorization, backend-api-design, cloud, networking
Type d'issue
Fonctionnalité
Difficulté
5/5
Temps estimé
Plus d'une semaine
Activité
Active
Clarté
Plutôt claire
Accessibilité débutants
38/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.