Sdns – Lightweight, fast recursive dns server with dnssec support
github.com
github.com
Would love to see some support for Prometheus compatible metrics.
I work at Cloudflare on 1.1.1.1.
1.1.1.1 supports DNS over HTTPS using Cloudflared. https://developers.cloudflare.com/1.1.1.1/dns-over-https/clo...
Our team actively maintains the repo.
Can you share what's been buggy about it?
Would love to share your feedback with the team.
Cheers!
docker run -d --name sdns -p 53:53 -p 53:53/udp -p 853:853 -p 8053:8053 -p 8080:8080 sdns
Give me a secure DNS box or do I have to do the TLS myself with say let’s encrypt?
You will need to obtain a suitable TLS certificate (for which you will have generated a private key).
For this to be of practical use outside of a toy, you will probably need to obtain the certificate from a different CA since you would want an ipAddress SAN (a certificate for the IP address of your DNS server, not the hostname) so that remote systems can use this server without also needing DNS, since if they have perfectly good DNS why use this server?
For a toy you can self-sign a certificate and set your test systems to trust that self-signed cert or whatever.
- Will a hipster javascript thing really be as reliable? Are these new runtimes really sufficient for totally essential things like email? What about filesystem stuff? I'd think a battletested thing like postfix will be much better off than this. - Do I really want to deal with javascript or whatever other hipster language for deployment? With most essential utilities, it's packaged in my distro with minimal dependencies. With hipster stuff, it's usually a fast pace of development, which doesn't lend itself to packaging, and uses something awful like npm. Is this something I really want to depend on?
So I'd wonder the same thing about sdns. The "rewrite it in ${safelang}" trend tends to produce immature and unreliably deployable software and that makes me worried. How's sdns fare?
Unbound seems generally respected, is nice and simple, written cleanly, and does MUCH less than bind. However it has had at least one memory corruption bug that plagues most c/c++ applications of non-trivial complexity. It also does seem to hang and I ask around and other people have seen similar. It's no longer what I consider reliable enough to be installed on every client. It's scary that it hangs, because if it gets that wrong there's likely other issues as well.
I'm hopeful that SDNS is more reliable and secure. I just want a local caching resolver that understands DNSSEC.