Migrating Mess with DNS to Use PowerDNS
jvns.ca
jvns.ca
In this particular instance I recall the post about DNS some years ago and the callback is amply enriched.
Keep it up @jvns. You hold us all to a high standard.
I noticed that you are using our Go module to access the API. It is wonderful to see our work helping others build great software, especially for education. Thank you for that.
Please note that the upstream API sometimes changes slightly between minor releases. For example, prior to v4.9, the error response for a non-existent server was "Not Found". Starting with v4.9, it changed to "Method Not Allowed".
Unfortunately, error responses aren't always part of the API specification. I'm thinking about adding the most common cases to the module anyway.
You mentioned about your previous version:
> If there was a CNAME record for a domain name, it allowed you to create other records for that domain name, even if it shouldn’t
> you could create 2 different CNAME records for the same domain name, which shouldn’t be allowed
One suggestion... If someone makes a mistake and generates an error, it would be terrific if there were a more verbose explanation so the user may better understand why what they're trying to do won't work. I'm very much a conceptual learner. If I can understand why an error is an error, it puts me on a better path toward a more comprehensive understanding.
Thanks again for all your work.
Found this a little surprising - postgres is internet old - I'm pretty sure it was around at a time when physical servers might not have 256mb of ram?
Seems this should be possible to tune down still? (I mean, maybe not. Postgres 16 isn't postgres 6, and maybe I'm just getting old..)
Given it can read BIND files, surprised BIND is still the default in many places.
I'm putting "account" between quotes because it isn't a PowerDNS concept, there is just a lonely varchar column in the 'domains' table where one can store some account-related information. To handle TSIG keys I had to extend PowerDNS's data model to represent the association between a TSIG key and an "account".
You may be able to implement the logging by using a customization of the Sqlite backend, although I think PowerDNS caching may get in your way.
I'll recommend the pipe backend to anyone looking to hack on DNS stuff. It's almost like a DNS lookup via a function in any programming language you choose. It takes a while to figure out how incoming queries are translated though.
I may consider extending the service to allow A/AAAA records to private IP ranges, and then I'd need a more full featured API, but this far there hasn't been demand for the feature.
Hit me up on email if you want to chat more (in profile), we're solving some similar problems.
Long before Bert was writing articles on the source code of mRNA vaccines, he helped build PowerDNS. He talks about that in a three part series starting here: https://berthub.eu/articles/posts/history-of-powerdns-1999-2...
A fascinating individual...
> i quit my job just over 5 years ago to explain computer things (https://jvns.ca/blog/2019/09/13/a-year-explaining-computer-t...). I had no idea if I would like being my own boss but ultimately it's been really cool and I'm happy to have this weird job writing zines about computers.
[0] - https://github.com/coredns/coredns/blob/master/ADOPTERS.md
- dnsdist DNS application aware loadbalancer
- Opera Software dns-ui
Probably you ran out of memory (and configured the database incorrectly).