HNHacker News
TopNewBestAskShowJobs

dynip

222 karma · joined April 28, 2026

submissionscomments
dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
Your stuff also looks interesting for sure, you have some things that I have on my backlog. regarding my API keys I use python for the per-account access in bearer style and the TSIG keys work as per zone directly to PowerDNS. I only use the powerdns api on the hidden primary setup so the secondaries can run individual zone cleanup, tsig replicatio, axfr meta data etc as sidecars and forward replication for dns updates.

was there anything in particular you were thinking?

dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
Back again, "works easily" was a bit of an understatement :D at least when securiting the zones with TSIG sha256 and moving keys around in a secure maner (I had previously used md5 because of compability with fortigate) there is full support now to the extent that I can test with rfc 2136, there is a guide and docs available at https://dynip.dev/docs#integration-external-dns and https://dynip.dev/guides/external-dns and a complete snippet generator. Read the notes as there are a few considerations on policy and depending on mode.

Please have a go if you can and report back if you feel like it

Thanks!

dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
Did a manual validation, have a go :)
dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
I triggered a resend on all emails that was not verified so possibly you have a new validation token available.
dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
Give me you address and I will have a look
dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
Well, if your current gripe is no Let's encrypt with NO-IP, then you have just found something that stands out for you :)
dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
Marking as fixed, was a prior html change that i overlooked

please have a go but right now it should not matter if you are logged in or not, the reset_token takes precedence.

Thanks for reporting!

dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
Thanks, will look into what the best path would be. adding to the bugs list :)
dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
mycket viktigt :)

Have not come in contact with Hickory DNS before, looks pretty solid

dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
Hi, just wanted to check in again to clarify this a bit. TSIG keys are used for both the api and the direct dns update, this is what authenticates the request and tied to a specific domain. the bearer (long and short) are for the account and is tied to you rather than a specific domain. https://dynip.dev/docs#api-register - you can also list current keys etc for the different domains.

https://dynip.dev/docs#authentication

TSIG Keys: Used strictly for updating DNS records (/update). These are 44-character Base64 encoded strings generated per-zone.

JWT Bearer Tokens: Used for account management and programmatic zone registration (/register). Generated upon user login.

Hope this helps to clear it up, I might link the documentation from the pricing section so that at least there is clarification on it.

dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
For sure!
dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
Good points, don't be sorry. At this point in time there are knowns and unknowns, hopes and dreams and a big chunk of tech knowledge. Not as big on the design part but I think its ok for now
dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
It has to do with the .dev root zone that needs to have these as records, I am on it but it might take a few days to get those records up. Or it could be fast. Glad that you reported and I will report back when we expect it to work
dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
Interesting, will do some digging on what sets them apart from the x amount of byod already precent. Thanks for letting me know!
dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
Wow, that sounds like a great idea. I wanted it to be easy with the paddle integration but even that was a pain. Will look into it for sure, thanks!
dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
Dynip.dev solves with dns challenge and you can download the full chain and key either via api or the dashboard. Check /docs
dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
Hi, doing on mobile so short answer. To my knowledge they don't do RFC 2146 but rather base everything around a good api that they have. Like you say different types of records etc.

And really, dynip came to be from fortinet/fortigate that have excellent support via their genericDDNS setup and things keep of of grew from there to what you see today.

And the subnet ipv6 sounds really interesting. Will need to check that out, sounds like that could be a feature request

dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
Thanks for all the excellent comments and questions, I will be bringing my daughter for swimming lessons for a few hours and will continue looking at the threads when I return.

Again, this guy <- happy

dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
point taken
dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
So many self replies :) happy to dive in a bit more at a later time to get your take on how the services work together. hope you found the /guide helpful
dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
This makes me really happy, like really really. It is the exact part of the /guide where things work together and not agaist or replace, synergy and happiness.
dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
I like to believe that there are different use cases that play with different needs, I don't know your exact needs on the topic but it sounds like you have figured out what needs you have on a technical basis.

The idea is not really to never expose anything, almost the opposite or at least understand where on the internet different things live and be able to address them globally

dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
Something to look into for sure. thnks
dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
Thanks, I will put it on my issues list to look into.
dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
Thanks, appreciate it!
dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
It is not, the functionality is the same. I am trying to expand on the functionality to not only support a single setup. we support multiple update paths, validation, DNSSEC, Letsencrypt, byod domain etc. fleet management. It could be a battery powered esp node that you send to another country. there are multiple ways of doing the same thing and what I hope I am doing is making it accessible, easy and good looking.

Fortinet for example have a similar thing, you can within their web interface register a something.fortiddns.com or float-zone.com or others. but if you upgrade the fortigate with a newer model you need to get in touch with their support because the domain is locked to the old hardware.

syncology has their own, I mean there has never been more options, what I am doing is trying to bundle, connect and provide a platform for your own domains, that can support letsencrypt out of the box, that you can use multiple update paths with ipv6 if needed.

long reply, I am genuinely happy for the "why" questions as it allows me to speak about the platform :)

dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
Thanks for that, My intentions are to stick around for sure. It is genuinely difficult to get a point across in a very short amount of time that people that people will actually recognize. its like doom scrolling where you just get boored of it. Happy to take suggestions.

< is there anything else you would like me to answer or is that good enough - GenericAI answer>

But jokes aside, words are difficult and also not my first language

dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
I run dynip.dev, there are like dynip . com that is retired, then there is dyndns and 100 different players i am sure, I am looking out to see if this is good, can be better or useless to the general public.
dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
The hidden primary has a passive node, so saying multiple multiple maybe is an overstatement :) and yes, using a single postgres container
dynip··on DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD
I know right, and you would try different themes, go into the code, try to delete footer information that pointed back to the theme maker only to break the structure of everything.
Page 1 of 2Next →