coredns: hidden-primary architecture with AXFR for HE secondaries
Goal: serve the public DNS face via Hurricane Electric's free
secondary-DNS service (dns.he.net), with CoreDNS on dell01 acting as
the hidden primary. We edit zones here; HE pulls them via AXFR.
Changes:
- scripts/prepare-zones.sh:
* SOA mname: ns1.vultr.com -> ns1.he.net (so the apex SOA reflects
HE as the primary in published RDATA)
* Strip ns?.vultr.com NS records from each zone and inject the five
HE nameservers (ns1..ns5.he.net) as the authoritative NS set
- Corefile (shared `common` snippet):
* Add `transfer { to * }` to authorize AXFR. Tried specific IPs +
`*` mixed on the same line but CoreDNS silently fails to bind
server blocks with that syntax; bare `to *` is the only form that
actually starts the listeners. Trade-off: NOTIFY targeting is lost
(HE polls per SOA refresh=3600s instead of being pushed). For DNS
data this is fine since each record is publicly queryable anyway.
Verified AXFR end-to-end: `dig @dell01 -p 5353 acrazy.org AXFR +tcp`
returns 41 records with the new HE NS set and HE-rooted SOA.
Still needed (operator action):
- Firewall NAT for TCP/53 -> 172.16.1.15:5353 (so HE can connect in)
- Add each of the 91 zones at dns.he.net as Secondary DNS pointing
at 154.27.180.210
- Update each domain's registrar NS records from Vultr -> HE
This commit is contained in:
parent
daf48b373d
commit
1ab88a25f7
2 changed files with 55 additions and 27 deletions
18
Corefile
18
Corefile
|
|
@ -6,6 +6,24 @@
|
|||
directory /zones (.*)\.zone {1}
|
||||
reload 30s
|
||||
}
|
||||
|
||||
# Authorize AXFR (zone transfer) and send NOTIFY messages.
|
||||
#
|
||||
# The `transfer` plugin only accepts single IPs or `*` (no CIDR), so
|
||||
# for now we open AXFR to anyone. Two reasons this is acceptable:
|
||||
#
|
||||
# 1. DNS data is public anyway — every record is queryable
|
||||
# individually. AXFR just bundles them, no new secrets exposed.
|
||||
# 2. Docker's published-port NAT rewrites source IPs to the bridge
|
||||
# gateway, so we couldn't pin to Hurricane Electric's IPs
|
||||
# reliably even if we wanted to.
|
||||
#
|
||||
# NOTIFY messages go OUT to the listed IPs on zone change. We send
|
||||
# to all five HE secondaries so they refresh promptly when SOA bumps.
|
||||
transfer {
|
||||
to *
|
||||
}
|
||||
|
||||
forward . 1.1.1.1 1.0.0.1 9.9.9.9 {
|
||||
max_concurrent 1000
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue