7 ms·
Self-Hosting DNS
- shivajikobardan 2y agoI also want to selfhost variosu servers like dns, email(just to send email to myself).....ldap, dhcp etc. Where do I get started with? I know linux command line.
- thbb123 2y agor/selfhosted on reddit has a very helpful community. DNS is very easy. Email is tough. Usually one would add a media server such as Plex and Nextcloud which is very useful.
- onlyspaceghost 2y agoMy journey of DNS, including self-hosting with Pi-hole and AdGuard Home, using paid services like NextDNS and AdGuard DNS, and public privacy-respecting resolvers.
- globular-toast 2y agoWhy forward requests to a DNS server like 1.1.1.1 at all? I used to use stuff like pi-hole/dnsmasq, but now I'm using unbound on my opnsense router which supports using blocklists and custom overrides (as well as automatic for DHCP clients). I found the default blocklists in pi-hole broke a few things but not had any problems with the lists I'm using now.
- swiftcoder 2y agoYou have to forward requests that aren't in your cache, surely? I don't see how you would resolve public domain names otherwise
- mavhc 2y agoUse the root servers to find the dns entries yourself, just like the upstream provider does
- sulandor 2y agothat's called a dns-resolver (iterator). essentially starting from the top (.) and asking for authorative nameservers that can answer the next level down until it reaches the hostname you are looking for. this usually takes multiple rtt's and is hence slower than asking some big cache.
- globular-toast 2y agoYes but to the root servers, not to someone else's cache.
- swiftcoder 2y agoI don't really see how this scales, on a global basis. Sure, one or two of us running our own resolvers isn't going to hurt, but an extra hundred million or so resolvers would hurt -> at best just causes all the servers targeted by the resolver to add more layers of caching
- globular-toast 2y agoIt's a good point, I never really thought about it. In my case I'm reluctant to use my ISP servers because my country tries to practise censorship via DNS, but I also didn't really feel like using something like Google. I will do some research and experimentation with upstream caches like Quad-9 and Cloudflare to see what it's like.
- tmottabr 2y agoDNS is highly distributed. I doubt the current infra would have any problem handle the load even if all individual devices had a local resolver.
- globular-toast 2y agoReplying again as I did some research. It turns out there aren't actually only 13 root name servers, there are almost 2000. Also, the vast majority of queries to the root servers are from badly configured systems that aren't caching results properly or aren't even receiving the results. So running your own caching resolver, assuming it's working correctly, would contribute to the small drop in the ocean that is legitimate usage of the root servers. Presumably the same applies to the next levels up too.
- nobody9999 2y agoThat would be a 'recursive resolver'[0], which recursively queries the DNS hierarchy from the top, returns the requested DNS record, and (unless you configure it not to do so) caches the results. They're easy to set up and unless you're using it to support thousands of DNS requests per second, it's not appreciably (on human scales) slower than forwarding requests to your ISP's servers and/or 8.8.8.8 or 1.1.1.1. More detail about recursive resolvers and how they work can be found here[1] [0] https://notes.networklessons.com/dns-recursive-resolver https://notes.networklessons.com/dns-recursive-resolver [1] https://www.akamai.com/glossary/what-is-recursive-dns https://www.akamai.com/glossary/what-is-recursive-dns
- ThePowerOfFuet 2y ago>I wanted to be able to access it with a static IP, and I don’t feel like calling my ISP to get one. Not "feeling like" calling your ISP to get a static IP, but also wanting to self-host?
- senectus1 2y agoI really resent having to pay $120 a year for a static IP :-|
- sulandor 2y agovps with static ip will go for half of that
- mftrhu 2y agoMake it a tenth. I have two small VPS with two different providers, and I am paying a total of $25/year for them.
- senectus1 2y agoI'm a bit old fashioned. its not self hosting if you dont hold the hardware :-P
- BenjiWiebe 2y agoWhat about if you use the VPS for a wireguard tunnel, so your beefier server at home has a public IP? Does that count? It's what I'm doing since we switched ISPs and now we are behind CGNAT (better connection otherwise though).
- vachina 2y agopoint your ns to CloudFlare and write a powershell script to update your AA records every 5 minutes, boom quasi static IP (from the PoV of the client anyway) Not 99.9999% uptime obviously but good enough.
- bananapub 2y agoDNS resolver, which it is deeply silly to not include in the title.
- sulandor 2y agotechnically it's a stub forwarder. so i'll let it pass
- deleted 2y ago[deleted]
- voytec 2y agoAgree. Title got me hoping for a description of reasonably-solved public zones self-hosting. The actual content is not interesting to me, and reads like an ad for something called AdGuard (I use unbound for most of this).
- onlyspaceghost 2y ago> reads like an ad for something called AdGuard (I use unbound for most of this). Definitely not an AD - it's just the best option that I found, and have been super happy with it! There are lots of ways to do this (people have shared even more options in the comments here), and for a lot of people AdGuard/Pi-hole/... are the relatively easier options
- endre 2y agosame here, bait title as it is
- onlyspaceghost 2y agoI haven't gotten this deep into it yet, but I hope to! It's very interesting - will try to be clearer next time :D /gen
- sulandor 2y agothis seems like a massively overcomplicated exercise. dns-blocking is evil, no matter who does it. stop lying to yourself and install contentblocker on your devices
- otabdeveloper4 2y agoDNS is a kind of content. You seem to be quibbling over semantic technicalities.
- sulandor 2y agonot really. it's about the blocking occurring in reach of the user (client) or not (infrastructure quirk that has to be worked around)
- otabdeveloper4 2y agoDNS isn't "infrastructure". It's just a simple key-value store, like Redis or something.
- sulandor 2y agodns more or less was infrastructure for the last 30 years. nobody cared. the fact that for-profit shops wanted a piece of the intelligence within made it surface and now the webheads are shitting on it like there is no tomorrow
- otabdeveloper4 2y agoNah, BIND is just really shitty software, so everybody thought that DNS must be mystical and special. Run a better DNS server and see for yourself that there isn't any man behind that curtain.
- creesch 2y ago> dns-blocking is evil, no matter who does it. You really ought to expand on that line of reasoning in order to get anyone to take this comment seriously.
- gbrindisi 2y agoI run coredns with a blocklist, the config is like 4 lines. What am I missing by not using AdGuard, PiHole and similar?
- _joel 2y agoA funky UI, I suppose and blocklist updating etc. But functionally, nothing, they're doing the same thing.
- jakobjs 2y agoFun project. But I would just use https://pi-hole.net/ https://pi-hole.net/
- Alifatisk 2y agoI’d like to see a comparison
- progbits 2y agoHalf of the article is literally a comparison between pihole and adguard...
- Alifatisk 2y agoReally? Because what I got out from the article was a table that did a comparison then the rest of the was focused towards AdGuard. But I found a thread on r/selfhosted that was more about comparing these two.
- onlyspaceghost 2y agoI apologise that it wasn't as clear as it could've been! What I was trying to get at is that for my requirements Pi-hole simply can't do it all without faff (DoH being the main one).
- Alifatisk 2y agoNooo, please do not apologize, your article was excellent and entertaining. I think it fulfilled its goal with what you were trying to convey!
- Havoc 2y agoHave used both for years - AGH is the better experience imo. eg DoH works out of the box
- Schwobaland 2y agoWant to throw in blocky (https://github.com/0xERR0R/blocky https://github.com/0xERR0R/blocky). Supports modern protocols and easy to configure in one file. Migrated to this from pi-hole and never looked back.
- onlyspaceghost 2y agoThis looks super cool! Will try to find some to compare it to the setup I'm on now
- tycoon177 2y agoBlocky is great! The maintainers are also really easy to get along with. I had a few features I needed to get off of pihole (cnames, defining DNS via zone files) and they worked with me to plan the feature and were very kind and responsive with reviews of my pull requests :)
- thedanbob 2y agoI recently switched from Pi-Hole to AdGuard Home, it was pretty straightforward to migrate my configuration and so far it's working great. I've actually got two servers running AGH + unbound (authoritative) so my internet keeps working if one setup breaks/reboots.
- Havoc 2y ago> By using multiple different resolvers, operated by different companies, no single one gets the whole picture. I’d say exact opposite. Now you’re sharing data with multiple parties and each is potentially getting enough data to extrapolate the whole picture
- packetlost 2y agoDoes anyone know of a good authoritative DNS server that supports Dynamic DNS updates? Preferably exclusively standardized stuff. I currently run CoreDNS on my network, but dynamic registration isn't supported and might never be.
- simpleTaffy 2y ago[dead]
- zuntaruk 2y agoDepending on your definition of "Dynamic DNS", you could check out PowerDNS.
- packetlost 2y agoI mean specifically in the RFC2136 (https://datatracker.ietf.org/doc/html/rfc2136 https://datatracker.ietf.org/doc/html/rfc2136) sense. It does look like PowerDNS supports it: https://doc.powerdns.com/authoritative/dnsupdate.html https://doc.powerdns.com/authoritative/dnsupdate.html
- zuntaruk 2y agoTIL more about Dynamic DNS Update. Thanks!
- johnea 2y agoAparently signing up for a subscription service now qualifies as "self-hosting" 8-) I've been running bind9 on a computer under my desk for about 20 years. The only subdscription required is an ISP contract that includes static IP. Maybe I'll get a netflix acct (never had one), and "self-host" some videos...
- onlyspaceghost 2y agoThe post was about self-hosting, not about the subscription. I do think the subscription is a good way to do it though!