#dnsdist — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #dnsdist, aggregated by home.social.
-
Today's open source bug report day I guess
https://github.com/PowerDNS/pdns/issues/16712
#PowerDNS #dnsdist -
There's an interesting conversation going on on the #NANOG #mailinglist. It's about running a #DNS resolver for a medium-sized service provider network:
Recommended DNS server for a medium 20-30k users isp
I particularly love that the people from @quad9dns chipped in, and revealed how they split their front- and backend with #dnsdist. Splitting the front- and backend of internet-facing services is something that I already learned in University as a best-practice.
-
There's an interesting conversation going on on the #NANOG #mailinglist. It's about running a #DNS resolver for a medium-sized service provider network:
Recommended DNS server for a medium 20-30k users isp
I particularly love that the people from @quad9dns chipped in, and revealed how they split their front- and backend with #dnsdist. Splitting the front- and backend of internet-facing services is something that I already learned in University as a best-practice.
-
PowerDNS Security Advisory 2025-02 for DNSdist: Denial of service via crafted DoH exchange
Impact: Denial of service
Exploit: This problem can be triggered by an attacker crafting a DoH exchangeCVE-2025-30194
https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2025-02.html
-
-
-
@SIDNlabs Thanks for contributing to the #DNS resolution diversity.
The original part is that you use many proxies (@PowerDNS #dnsdist ) and only a few backends (@nlnetlabs #unbound ). I know by experience that both work well together (esp. with PROXYv2).
What were the advantages (practical, technical, financial) that lead to this setup?
Also, do you share cache between nodes either at the proxy or backend (cachedb)? -
Ah bah finalement pas de #DoH3 et #DoQ pour @DNS_Shaftinc 😢
Je pensais que quiche, la bibliothèque de Cloudflare pour faire du Quic, était dans le tarball de #dnsdist, mais après vérif, il y a plutôt un script qui télécharge quiche et compile le truc.
Meh :/
-
Ah bah finalement pas de #DoH3 et #DoQ pour @DNS_Shaftinc 😢
Je pensais que quiche, la bibliothèque de Cloudflare pour faire du Quic, était dans le tarball de #dnsdist, mais après vérif, il y a plutôt un script qui télécharge quiche et compile le truc.
Meh :/
-
you know, it is always great when you report an issue and it actually gets fixed.
Like what happened today! https://github.com/PowerDNS/pdns/pull/14081
-
PSA: don't update to #dnsdist 1.9.2 as it contains a crasher regression. 1.9.3 will be released soon.
-
PSA: don't update to #dnsdist 1.9.2 as it contains a crasher regression. 1.9.3 will be released soon.
-
I been having my #dns set up not be the best with failover in the #homelab . Right now i'm using #dnsdist as a dns load-balancer. It can use the Proxy-Protocol to pass source IP to the backend dns server that also has this capability. Here is the problem. The health checking mechanism #dnsdist has doesn't play nice with my DNS. So I have to force the backend services up! Well, when the backend dns goes down, #dnsdist doesn't know that and still try's to pass it traffic and it's all bad.
-
I been having my #dns set up not be the best with failover in the #homelab . Right now i'm using #dnsdist as a dns load-balancer. It can use the Proxy-Protocol to pass source IP to the backend dns server that also has this capability. Here is the problem. The health checking mechanism #dnsdist has doesn't play nice with my DNS. So I have to force the backend services up! Well, when the backend dns goes down, #dnsdist doesn't know that and still try's to pass it traffic and it's all bad.
-
@[email protected] @wutti Good candidate for upstream DNS encryption provider might be also #dnsdist. Versatile thing with also DoH and DoQ support, which could be used together with pihole's dnsmasq. But haven't tried to compile it on openwrt myself. Visit dnsdist.org for help.
-
I'm not exactly sure how I got here! I been trying to figure out my DNS infra for some damn reason. It's DNS who the fuck cares. I can't let it go!
I just want to exercise my second DNS server, cause it's just there. So lets put #dnsdist in front of it, solid!. It gave me a promfana endpoint to see shit. Dope! Then I'm like I want that for my DNS servers! Insert #coredns. It's coo! Fast! Easy to use! Ad blocking, not so much. Insert #blocky. Ok WTF is going on!
-
I'm not exactly sure how I got here! I been trying to figure out my DNS infra for some damn reason. It's DNS who the fuck cares. I can't let it go!
I just want to exercise my second DNS server, cause it's just there. So lets put #dnsdist in front of it, solid!. It gave me a promfana endpoint to see shit. Dope! Then I'm like I want that for my DNS servers! Insert #coredns. It's coo! Fast! Easy to use! Ad blocking, not so much. Insert #blocky. Ok WTF is going on!
-
Been on this DNS kick in the #homelab. I'm really enjoying g #dnsdist as a #dns loadbalancer with #coredns backing at least one of my servers. I'm going to add 2 more dns servers to the mix and have them funnel down to an adblocker type! I'm still thinking about nextdns. I just can't seem to get over paying for something that you can do with pi-hole or the likes.
-
Spent a good time with #dnsdist as a #dns load balancer and it works seems to be working pretty well so I don't just have a second DNS server just chilling. I tried to get the source ip address to get passed to the backend but still missing something there. Good to get back into the #homelab #selfhosting #selfhosted
-
In other news, all of our domains fell off the internet for a couple of minutes. The reason? DNS. It's always DNS ;-) I did some autumn cleaning and restructured and simplified the way we're doing DNS here. It's a pretty neat setup based on #dnsdist and #PowerDNS. Unfortunately, I managed to screw up the TSIG key, and the newly reinstalled DNS servers were unable to do domain transfers from the hidden primary PowerDNS server, so - no DNS entries for you! :-) Error was fixed fast, and we're back online - fast and resilient as fuck. At least when it comes to handling DNS queries.
-
#dnsdist wil get DoQ support from the next release, meaning so will UncensoredDNS. Looking forward to it!
-
Wow, la conso mémoire de #dnsdist 1.8.0, c'est quelque chose. Sur la 1.7.x on était stable à env. 60 Mo, et là on est déjà à 114 Mo à trafic constant (env. 1,3 req/s qui arrivent)
Je ne vois rien dans le changelog qui indique un possible changement de comportement (ou un changement de la métrique).
J'ai de la marge sur la machine (usage de la RAM : 33%), mais je vais continuer à surveiller
-
@JerryMouse @iampytest1 Hello fellow #dnsdist users! Maybe you will find my dnsdist-utils useful? https://github.com/hhoffstaette/dnsdist-utils