osbase/net/dns/kubernetes: add Kubernetes DNS handler

This adds a DNS server handler for Kubernetes DNS service discovery. It
is partially based on the CoreDNS Kubernetes plugin. The query handler
however is written completely from scratch. The handler in the CoreDNS
plugin is very weird; it first handles each query type separately, and
generates msg.Service objects which then need to be converted to dns
records. The new implementation is much simpler, and also more correct:
It handles ANY queries, and follows the rules for NXDOMAIN (If a name is
NXDOMAIN for one qtype, it is NXDOMAIN for all qtypes, and subdomains of
the name are also NXDOMAIN.)

Change-Id: Id1d498ca5384a3b047587ed73e95e4871d82d499
Reviewed-on: https://review.monogon.dev/c/monogon/+/3259
Reviewed-by: Lorenz Brun <lorenz@monogon.tech>
Tested-by: Jenkins CI
diff --git a/osbase/net/dns/kubernetes/kubernetes.go b/osbase/net/dns/kubernetes/kubernetes.go
new file mode 100644
index 0000000..efcb60e
--- /dev/null
+++ b/osbase/net/dns/kubernetes/kubernetes.go
@@ -0,0 +1,47 @@
+// Package kubernetes provides the kubernetes backend.
+package kubernetes
+
+// Taken and modified from the Kubernetes plugin of CoreDNS, under Apache 2.0.
+
+import (
+	"context"
+	"net/netip"
+
+	"github.com/miekg/dns"
+	"k8s.io/client-go/kubernetes"
+
+	"source.monogon.dev/osbase/supervisor"
+)
+
+// Kubernetes is a DNS handler that implements the Kubernetes
+// DNS-Based Service Discovery specification.
+// https://github.com/kubernetes/dns/blob/master/docs/specification.md
+type Kubernetes struct {
+	clusterDomain string
+	nsDomain      string
+	ipRanges      []netip.Prefix
+	// A Kubernetes ClientSet with read access to endpoints and services
+	ClientSet kubernetes.Interface
+	apiConn   dnsController
+}
+
+// New returns an initialized Kubernetes. Kubernetes DNS records will be served
+// under the clusterDomain. Additionally, reverse queries for services and pods
+// are served under the given ipRanges.
+func New(clusterDomain string, ipRanges []netip.Prefix) *Kubernetes {
+	k := new(Kubernetes)
+	k.clusterDomain = dns.CanonicalName(clusterDomain)
+	k.nsDomain = "ns.dns." + k.clusterDomain
+	k.ipRanges = ipRanges
+	return k
+}
+
+// Run maintains the in-memory cache of Kubernetes services and endpoints.
+func (k *Kubernetes) Run(ctx context.Context) error {
+	k.apiConn = newdnsController(ctx, k.ClientSet)
+	k.apiConn.Start(ctx.Done())
+
+	supervisor.Signal(ctx, supervisor.SignalHealthy)
+	<-ctx.Done()
+	return ctx.Err()
+}