Email for your domain, with DNS setup handled. PostScale

    Sign Up
    Product Updates

    Manage Kubernetes DNS with the DNScale ExternalDNS webhook

    Keep DNScale application DNS aligned with Kubernetes Services and Ingresses using the new ExternalDNS webhook and scoped TXT ownership.

    Version 1.0.0 of the DNScale ExternalDNS webhook is available with public container images and configuration for the official ExternalDNS Helm chart. Kubernetes teams can now keep application DNS aligned with their Services and Ingresses through the DNScale API.

    Follow application changes

    ExternalDNS watches selected Kubernetes resources and calculates the DNS changes they require. The DNScale sidecar handles zone discovery, record updates, and selected-value cleanup. It supports IPv4 and IPv6 addresses, hostname targets, multiple IP targets, and TTL changes.

    For example, a LoadBalancer Service can declare web.k8s.example.org through an annotation. When its published address changes, ExternalDNS updates the corresponding DNScale record. Under sync, deleting the resource also removes the controller's DNS and ownership metadata. With upsert-only, that DNS remains in place after resource removal.

    Start with a dedicated scope

    The supplied configuration uses explicit domain and zone filters, a token mounted from a Kubernetes Secret, and a stable TXT owner ID. One controller owns each complete name/type record set. Keep Terraform, DNSControl, and manual writers outside those record sets.

    Installation starts with the sidecar's DNSCALE_DRY_RUN=true. This setting is necessary because the tested upstream controller does not forward its own dry-run flag through the webhook protocol. Review the scope and selected resources, enable upsert-only writes, then test deletion before choosing sync.

    The provider re-reads state before applying changes and supports retries after partial writes. Ownership metadata is created before data and removed after data cleanup, allowing a restarted controller to recover without an in-memory record-ID cache. This does not provide atomic batches or coordination between independent writers.

    DNS and certificates in Kubernetes

    ExternalDNS manages application addresses. The DNScale cert-manager webhook handles ACME DNS-01 validation for certificates. They can share a zone with separate ownership: application records and edns- TXT markers for ExternalDNS, _acme-challenge TXT values for cert-manager.

    This release targets ExternalDNS 0.23.0, chart 1.23.0, and Kubernetes 1.35.0. It does not add wildcard DNS names, routing policies, automatic zone creation, or apex CNAME flattening.

    Follow the ExternalDNS setup guide, view the changelog, or browse the source and examples.

    Managed authoritative DNS

    Run DNS with observability built in

    Start free, then move to Scale or custom plans when you need DNS traffic alerts, higher query volume, and dedicated human support.

    More from Product Updates