Skip to content

Publish private DNS names for compute instances - #451

Draft
scotwells wants to merge 5 commits into
mainfrom
feat/internal-dns-instance-publishing
Draft

scotwells wants to merge 5 commits into
mainfrom
feat/internal-dns-instance-publishing

Conversation

@scotwells

@scotwells scotwells commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Give Compute instances automatic private names in each attached VPC's datum.internal zone. Users attach workloads to a network without choosing a DNS zone or maintaining address records.

User experience

Names follow the instance lifetime and use <allocated-instance-name>.datum.internal. Instance.status.dns reports assigned hostnames and publication readiness per network. Application readiness does not remove an instance identity name.

Publication requires a current VPC resolver context, a separately issued scoped grant, and live edge network observations. Records expire when observations stop. The InternalDNSPublishing feature gate defaults to disabled.

Workload providers handle guest resolver delivery through the separate network services integration. Enablement requires project authorization, trusted grant provisioning, and read-only edge credentials. DNS domain allocation depends on datum-cloud/dns-operator#243.

Validation

make test, repository lint, publisher race tests, and the affected Compute package tests pass locally. Tests cover context identity, grant permissions, source and network lifetime changes, bounded renewal, and DNS status ownership. Guest-to-DNS qualification in the shared Kubernetes environment remains a release requirement.

Refs datum-cloud/enhancements#921 and #470.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant