Edit: forgot to mention, you can use static leases, too, permanently assigning an IP/hostname to a MAC address: just remove the expiration field in /perm/dhcp4d/leases.json :)
I have a live weather station [1] that pulls data from a Go-based service that I wrote and run on a server on my home network. When I'm outside of the house, mhkweather.com resolves to a Digital Ocean IP, where I run a proxy to forward requests back to home IP. However, when I'm at home, mhkweather.com resolves to a local 10.x.x.x IP and goes straight the the local service, no proxy. It faster this way. I want to be able to set DNS overrides for local things. I can do this with unbound but it would be nice if dnsd could do this for me.
For the time being, you’d need to modify dnsd to install your custom handler. It should be as simple as adding another server.mux.HandleFunc call in internal/dns/dns.go.
If this turns out to be a feature which many people would like, I’ll think about how to best structure the code to make this easier.
What I'd like to see is a home router that lets me put arbitrary rules in. Currently I use dnsmasq as a resolver and it basically does what I need, but I'd rather have it running on the router instead of needing another computer.
My current rule set is roughly:
* Resolve from local hosts file - this is where I put my statically assigned home servers/devices.
* If the domain request matches .domain.tld, forward it to a.b.c.d for resolution - this is a dnsmasq running on a remote box and covers off VMs that I run there. There is an IPSec tunnel (running on a small VM) and static routes on my router that handle getting to that box.
Finally, pass the request onto my router which will pass it onto my ISP or use its local DHCP-driven hosts table to resolve it.
I'd love it if an off-the-shelf router could do this. Currently I'm using a UniFi Security Gateway and it seems like this feature set would be a good fit. The router is professional-enough that advanced features like this make sense.
I’ve done Go cross-compilation for running on Ubiquiti gear before, and it worked. So, if you’re willing to spend the effort, you could do it :).
I run 2 dns servers usually on the same box on different bind addresses. You'd run a caching resolver on the gw ip and forward requests for my.tld to the second resolver which is configured to be authoritative for my.tld. the hosts can then be configured either through DHCP or statically.
This is a pretty common technique to make enterprises Intranets.
Added benefit is that when you did a file transfer between Lan hosts with the globally accessable DNS, the transfer stays on the LAN. Also ssh host works in you ssh config regardless of location.
I guess Go's cross compilation makes it easier.
PS: Without hardware offload, the 8 port POE switch only manages 12 megabits / second.
dnsmasq should be able to do what you want to do and it can be enabled on the USG - at least from the controller.
The "best way" is to use a real domain for your local network. But this can be annoying, costs money and has other issues (renaming/-branding, mergers/splits, domain squatting, accidental record publication and so on ---- it's a lot like renting an internet-routable IP network for LAN use, it's kinda silly and error prone).
For instance, I've got a tinc VPN network setup between many of my hosts. What IP range should I set that to such that it will not clash with whatever access network my laptop roams onto? The proper IP-philosophy answer is to apply for a block, even if it's never announced by BGP.
The pragmatic hack is to attempt to choose the most obscure block that isn't likely to conflict with the public Internet or with how local networks are generally setup. In my case, I chose something NOT from RFC1918 (so shoot me).
It's of course less of a big deal if you do realm / split-horizon based routing. But that is not straightforward to setup, as it's getting away from how IP was designed to be used.
I just learned this however: https://www.icann.org/resources/board-material/resolutions-2...
So .corp and .home will not become gTLDs and should be relatively safe to use.