CoreDNS: DNS service discovery for the cloud
coredns.io
coredns.io
It would be great if the site explained why it is different to the alternatives. If I was using Kubernetes for instances, why would I swap out the default service discovery mechanism for this one?
K8S uses SkyDNS and CoreDNS says it's a full replacement for sky just with more features. From quick eyeballing of the site, these new features include: serving from files instead of etcd, proxying requests, rewriting requests, doing healthchecks on endpoints, and publishing metrics into Prometheus.
Even without rate limiting attackers will spread it out because too much traffic coming from one DNS server can be easily blocked at the network level.
Many DDoS attacks will send a significant number of queries through any given DNS server to get a decent amplification. While normal clients will send 1 per TTL period. Yes, you can add servers at will, bit if everyone has RRL, your amplification factor is nearing zero.
The amplification factor is the ratio of the response size to a single packet. Not the number of packets you can send to a server.
The only thing the RRL helps with is forcing the attacker to spread packets over more DNS servers, but, as I pointed out, a good amplification attack already does this because it makes it harder for the victim to block DNS servers by IP.
The attacker isn't going to run out of DNS servers because there are hundreds of thousands authoritative ones, let alone open resolvers.
Why use dns at all?