I've never tried pairing it with Tailscale(I don't use it), but I pair it with Consul.
The config and docs aren't the prettiest, but it works fine. Most DNS software can't handle this use-case well.
I've never tried pairing it with Tailscale(I don't use it), but I pair it with Consul.
The config and docs aren't the prettiest, but it works fine. Most DNS software can't handle this use-case well.
For instance, we might have diff. source networks based on their department or building or whatever. We can then give them DNS information based on where they are coming from. It's not foolproof obviously, even if we control the internal network, it doesn't mean a bad actor isn't around wreaking havoc, so it's defence in depth, not the sole line of defence.
But it allows us to control DNS from 1 spot, and give this group of servers names for themselves, and that group of servers and this group of clients access to this group of servers, etc.