From 2162c7e2e46aab7e9e69180db051f7ad935784d9 Mon Sep 17 00:00:00 2001 From: Giordon Stark Date: Fri, 4 Sep 2026 01:22:25 -0500 Subject: [PATCH] docs: note dns_canonicalize_hostname=false may be needed --- README.md | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index 0e1a235..4dd4d12 100644 --- a/README.md +++ b/README.md @@ -249,7 +249,10 @@ privilege model this service needs: stance for its own trust material. Set `krb5Config.override: true` to instead render `krb5Config.contents` into a ConfigMap mounted over that same path via `subPath`, so a CERN KDC hostname change needs no image - rebuild. + rebuild. Depending on your resolver/network setup, you may need to add + `dns_canonicalize_hostname = false` under `[libdefaults]` in that + overridden config to stop the DNS lookup from canonicalizing the KDC + hostname — confirmed necessary at UChicago's AF. - **NetworkPolicy** — ingress only from the broker pods; egress limited to DNS, the broker JWKS origin, and the CERN KDC(s) `kinit` contacts, opened on **both UDP and TCP port 88** (all `ipBlock` rules, since these servers