Manage Kubernetes DNS with the DNScale ExternalDNS webhook
Keep DNScale application DNS aligned with Kubernetes Services and Ingresses using the new ExternalDNS webhook and scoped TXT ownership.
Version 1.0.0 of the DNScale ExternalDNS webhook is available with public container images and configuration for the official ExternalDNS Helm chart. Kubernetes teams can now keep application DNS aligned with their Services and Ingresses through the DNScale API.
Follow application changes
ExternalDNS watches selected Kubernetes resources and calculates the DNS changes they require. The DNScale sidecar handles zone discovery, record updates, and selected-value cleanup. It supports IPv4 and IPv6 addresses, hostname targets, multiple IP targets, and TTL changes.
For example, a LoadBalancer Service can declare web.k8s.example.org through
an annotation. When its published address changes, ExternalDNS updates the
corresponding DNScale record. Under sync, deleting the resource also removes
the controller's DNS and ownership metadata. With upsert-only, that DNS
remains in place after resource removal.
Start with a dedicated scope
The supplied configuration uses explicit domain and zone filters, a token mounted from a Kubernetes Secret, and a stable TXT owner ID. One controller owns each complete name/type record set. Keep Terraform, DNSControl, and manual writers outside those record sets.
Installation starts with the sidecar's DNSCALE_DRY_RUN=true. This setting is
necessary because the tested upstream controller does not forward its own
dry-run flag through the webhook protocol. Review the scope and selected
resources, enable upsert-only writes, then test deletion before choosing
sync.
The provider re-reads state before applying changes and supports retries after partial writes. Ownership metadata is created before data and removed after data cleanup, allowing a restarted controller to recover without an in-memory record-ID cache. This does not provide atomic batches or coordination between independent writers.
DNS and certificates in Kubernetes
ExternalDNS manages application addresses. The
DNScale cert-manager webhook handles
ACME DNS-01 validation for certificates. They can share a zone with separate
ownership: application records and edns- TXT markers for ExternalDNS,
_acme-challenge TXT values for cert-manager.
This release targets ExternalDNS 0.23.0, chart 1.23.0, and Kubernetes 1.35.0. It does not add wildcard DNS names, routing policies, automatic zone creation, or apex CNAME flattening.
Follow the ExternalDNS setup guide, view the changelog, or browse the source and examples.
Managed authoritative DNS
Run DNS with observability built in
Start free, then move to Scale or custom plans when you need DNS traffic alerts, higher query volume, and dedicated human support.