Okay, so I can't CNAME the root of my domain like I wanted to, and I don't think I'll be able to get around handing control of the whole zone file over to BIND. The point of my struggle was to separate out the dynamic update (and BIND's gross auto-formatting) from the "static" stuff that I don't want changing automatically.
I've settled on having a "static" file that I make updates to, manually push over to the path BIND uses, and forcing it to re-sync. I may script something smarter later, but this satisifies my OCD for now.
Gonna go run (NOW FAO, NOT LATER) and work on setting up the secondary later. Also on the list: XoT and DNSSEC.