Skip to main content

Configuration dns cluster: many webservers and 3 dns-only servers

Comments

5 comments

  • cPanelMichael
    Hello, The following feature request is open to help avoid this issue: Ownership and access control of zones in the dns server. If you use "Synchronize" instead of "Write-Only" as the DNS role, then it will prevent the creation of a DNS zone on a hosting server if it already exists. Thank you.
    0
  • bejbi
    Thank You for advice about changeing "Write-Only" into "Synchronize". I did it already when we were tested many configurations :-) It resovles problem with creating existing domain, but make another problem: When the webserver is set to Synchronize, root user in WHM can edit all zones (even is they are not on this webserver). i.e when original account with subdomain: mydomain.example.com is on webserver s1.example.com and I edit this zone on webserver s2.example.com then: Synchronize push my new zone form s2.example.com into dns-only servers. When the dns-only servers are still "standalone" they DON'T push this new zone update into original webserver: s1.example.com So we have problem - new version of zone exists on dns-servers, but original account where this zone is parked CAN'T see this changes. We can go further: When customer is editing his domain in his cPanel account (on webserver s1.example.com) this new update of zone, will overwrite existing zone in dns-only cluster ... So root/reseller and user can overwrite zones each other :/ W.
    0
  • cPanelMichael
    So root/reseller and user can overwrite zones each other :/

    There's no workaround to that issue at this time. It would require new functionality, as described at: Ownership and access control of zones in the dns server. Thank you.
    0
  • bejbi
    We find solution for this. It is under our investigation now: If I set on webservers role: Synchronize and on dns-only set Write only it look like works correcty: If I edit zone on "any" webserver - it push this zone into dns-only servers. And if dns-only is set to other servers in dnscluster in role "Write only" - so dnsserver pushes the updated zone into every webservers. After this, zones on every webservers still updated, and current. It is also very comfortable, becouse I can edit dns-zone on any webserver without trouble. Only disadvantage of this above is: when dns-only push updated zone, this zone (I mean: file on disk) will appear on every webservers. But this can I accept ... W.
    0
  • cPanelMichael
    Hello, I'm happy to see you were able to find a workaround that suits your needs. Thank you for updating us with the outcome.
    0

Please sign in to leave a comment.