Wondering if someone has come across this same issue and might have a solution. The story is I was originally using Unbound + Adguard and have since removed Adguard and just use Unbound.
I moved my override rule into Unbound that is a wildcard of my own domain I use for services in my Kubernetes cluster. I have cert-manager that manages the renewal of my certs through DNS challenge. I additionally have a 53 NAT rule to redirect back into Unbound. The problem is the Unbound override does TXT requests as well so my _acme-challenge.my.domain.com is being redirected to my reverse proxy causing it to never successfully renew.
What would be the best way to allow my Kubernetes cluster to bypass these rules so that cert-manager can successfully renew my certs without my manual intervention?
Source: r/opnsense · by /u/websheriffpewpew