external-dns - keep DNS records in step with Kubernetes Services, Ingresses and Gateway routes
external-dns --source=SOURCE... --provider=PROVIDER [--policy=upsert-only|sync] [--registry=txt --txt-owner-id=ID]
Options you will use
--source=service|ingress|gateway-httproute- where hostnames come from
--provider=rfc2136|aws|azure|google|cloudflare...- which DNS API it writes to
--policy=upsert-only- create and update, never delete (the safe default); sync also deletes
--registry=txt --txt-owner-id=ID- a TXT record next to every record it owns, so two clusters never fight over a name
--domain-filter=lab- only names in this zone
--interval=1m- how often it reconciles
Examples
$ kubectl annotate svc web external-dns.kubernetes.io/hostname=web.laba LoadBalancer Service gets an A record
$ kubectl logs -n external-dns deploy/external-dns"Adding RR: shop.lab 300 A 10.64.0.240"
Gotchas
- Since v0.22 the annotation prefix is external-dns.kubernetes.io/ (no fallback); old manifests with external-dns.alpha.kubernetes.io/hostname are ignored unless --annotation-prefix sets the old one.
Try external-dns in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.