@neil Internally, yes. FreeIPA doesn’t care about external domains because it doesn’t do views. For example, my domain angelsofclockwork.net. I have external records hosted somewhere else but my IPA domain is still angelsofclockwork.net internally, held by my IPA servers. Changes I do there do not reflect external changes. My external changes are done elsewhere. This system is doable.
Edit, here’s what I mean.
# dig mgt.angelsofclockwork.net @10.100.0.231 A
; <<>> DiG 9.11.20-RedHat-9.11.20-5.el8 <<>> mgt.angelsofclockwork.net @10.100.0.231 A
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 44108
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 3, ADDITIONAL: 7
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
; COOKIE: 8a05702cb5025ce046ce117d5fd1343321297e13edf40253 (good)
;; QUESTION SECTION:
;mgt.angelsofclockwork.net. IN A
;; ANSWER SECTION:
mgt.angelsofclockwork.net. 1200 IN A 10.100.0.10
;; AUTHORITY SECTION:
angelsofclockwork.net. 60 IN NS ipa02.angelsofclockwork.net.
angelsofclockwork.net. 60 IN NS ipa01.angelsofclockwork.net.
angelsofclockwork.net. 60 IN NS router.angelsofclockwork.net.
;; ADDITIONAL SECTION:
router.angelsofclockwork.net. 1200 IN A 10.100.0.1
ipa01.angelsofclockwork.net. 1200 IN A 10.100.0.231
ipa02.angelsofclockwork.net. 1200 IN A 10.100.0.232
router.angelsofclockwork.net. 1200 IN AAAA 2001:470:1f19:138::1
ipa01.angelsofclockwork.net. 1200 IN AAAA 2001:470:1f19:138::231
ipa02.angelsofclockwork.net. 1200 IN AAAA 2001:470:1f19:138::232
;; Query time: 0 msec
;; SERVER: 10.100.0.231#53(10.100.0.231)
;; WHEN: Wed Dec 09 13:31:47 MST 2020
;; MSG SIZE rcvd: 291
# dig mgt.angelsofclockwork.net @8.8.8.8 A
; <<>> DiG 9.11.20-RedHat-9.11.20-5.el8 <<>> mgt.angelsofclockwork.net @8.8.8.8 A
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 37100
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;mgt.angelsofclockwork.net. IN A
;; Query time: 19 msec
;; SERVER: 8.8.8.8#53(8.8.8.8)
;; WHEN: Wed Dec 09 13:32:27 MST 2020
;; MSG SIZE rcvd: 54