Lattice uses GSS-TSIG against AD-integrated zones. Starter and above include dns.ad_gsstsig. Community does not.
Console
- DNS servers → adapter
ad_gsstsig. Host is a DC. Principal e.g.DNS/[email protected].keytab_refisfile:/etc/lattice/lattice.keytab— never paste the keytab into the UI. - Subnet: DDNS on, adapter
ad_gsstsig, forward and reverse zones. - Worker:
LATTICE_GSS_TSIG_MODE=subprocess.nsupdateonPATH. Clocks vs DCs < 5 minutes.
Lattice does not talk LDAP. Updates are RFC 2136 with Kerberos. Failures retry in the outbox; Ack already happened.
What you need
- A keytab or equivalent for the Lattice service account
- Zone names that match the DHCP domains you serve
- Network path from
lattice-workerto a DC
Failure to update DNS does not roll back the lease. Operators see the DNS job status in the control plane.