İçeriğe atla
0
  • Ders Ara
  • Ana Sayfa
  • Kategoriler
    • All Categories
      • Individual Categories
    • Gruplar
    • Okunmamış 0
    • Güncel
    • Kullanıcılar
    • Hakkımızda
    • Öğrenci Fırsatları
    • Akademik Takvim
    • CV oluşturucu
    • IEU Timetable
    • Devamsızlık App
    • IEU GPA Hesaplayıcı
    • Niki Cüzdan
    • Ders Ara
    • Ana Sayfa
    • Kategoriler
      • All Categories
        • Individual Categories
      • Gruplar
      • 0 Okunmamış 0
      • Güncel
      • Kullanıcılar
      • Hakkımızda
      • Öğrenci Fırsatları
      • Akademik Takvim
      • CV oluşturucu
      • IEU Timetable
      • Devamsızlık App
      • IEU GPA Hesaplayıcı
      • Niki Cüzdan
      Daralt
      IEU Forum – İzmir Ekonomi Üniversitesi Öğrenci Topluluğu Platformu

      IEU Forum

      -- çevrimiçi
      1. Ana Sayfa
      2. Selfhosted
      3. How do people handle authoritative DNS redundancy for their self-hosted workloads?

      Final Unicourse'tan Çalış, Yüksek Notu Garantile!

      %25 İndirim Kodu: FRM25
      Yükleniyor...
      Dersi İzle
      GÖRÜNTÜLEYENLER
      +36
      Premium Özellik
      Bu konuyu kimlerin görüntülediğini görmek için Premium üyelik gerekir.
      Premium'a Geç

      Vizesine Unicourse'tan Çalış, Yüksek Notu Garantile!

      A B C D Çıkmış Sorular Formül Kağıtları Konu Anlatımı Sınav İpuçları Örnek Sınav
      Dersi İzle
      YENİ ÖZELLİK

      Bi'Öğrenci Fırsatları
      Forum'da!

      Bi'Öğrenci ile artık forum üzerinden en güncel indirimlere, anlık fırsatlara ve avantajlı tekliflere ulaşabilirsin.

      FIRSATLARI KEŞFET
      Red Bull Basement
      SPONSORLU ETKİNLİK

      Fikrini Gerçeğe Dönüştür

      Projeni dünyaya göstermek için sahne hazır. Red Bull Basement başvuruları açık.

      Başvurunu Yap

      🎉 Foruma Yeni Özellik Geldi!

      Sizin için PDF toollarını getirdik!

      İncele ve Kullan

      How do people handle authoritative DNS redundancy for their self-hosted workloads?

      Konu Zamanlandı Sabitlendi Kilitli Taşındı Selfhosted
      selfhosted
      1 İleti 1 Yayımlayıcılar 0 Bakış
      • En eskiden en yeniye
      • En yeniden en eskiye
      • En çok oylanan
        Cevap
        • Yeni başlık oluşturarak cevapla
        Cevaplamak için giriş yapın
        Bu başlık silindi. Sadece başlık düzenleme yetkisi olan kullanıcılar görebilir.
        • dave@lemmy.pootis.networkD This user is from outside of this forum
          dave@lemmy.pootis.networkD This user is from outside of this forum
          dave@lemmy.pootis.network
          yazdı Son düzenleyen:
          #1

          I'll just provide my own example: my homelab consists of 6 Kubernetes nodes placed across the country. Some differ by ISP, some are placed in different cities, one is hosted on a cloud provider. Basically it's a very cheap variant of geo-replicating my workloads.

          Two of these nodes are visible from the Internet and have a static IP address; one node also has an IPv6 address. Each node hosts an authoritative DNS server (CoreDNS) for my personal domain pootis.network; and the .network TLD has glue records which point to IPs of these two nodes. This is a classic "self-hosted DNS" scenario.

          Here's an excerpt from my zonefile so you can understand the setup better:

          $ORIGIN pootis.network.
          $TTL 300
          
          @       SOA     ns1.pootis.network. admin.pootis.network. (
            2026082001
            1200
            300
            1209600
            300
          )
          
          ; Nameservers and glue records
          @       NS      ns1.pootis.network.
          @       NS      ns2.pootis.network.
          ns1     A       178.44.116.85
          ns2     A       91.219.150.30
          ns2     AAAA    2a06:dd00:1:4::4189
          

          This 5-record block (NS/A/AAAA) is mirrored into the .network zone by my domain registrar (plus DS for DNSSEC but that's another thing).

          As such, my DNS becomes fully independent - and, in theory, if one of my externally-facing nodes breaks, let's say ns1, then DNS resolvers all over the world (forwarders, recursive, and such) will fall back to ns2, and everything will keep working. Kubernetes will also reorganize the pod placement so all my workloads are available again after a slight downtime.

          That would have been great, if it worked as described, but apparently, after one nameserver in my zone fails, then the resolvers... just give up? Let's say ns1 failed but ns2 is working. The parent zone still points to both nameservers. My external resource records (websites and other stuff) at this point would have already been auto-reconfigured by a custom k8s controller to point to the IP addresses of the node that hosts ns2. Simplifying: the entire world basically sees this after ns1 fails and after TTL caches expire:

          ; all of this has very low TTL, 5 minutes or so
          
          @       NS      ns1.pootis.network. ; from .network 
          @       NS      ns2.pootis.network. ; from .network
          
          ns1     A       178.44.116.85 ; broken. Either from .network glue or from my auth DNS
          ns2     A       91.219.150.30 ; either from .network glue or from my auth DNS
          ns2     AAAA    2a06:dd00:1:4::4189 ; same
          
          ; my-website     A       178.44.116.85 ; does not appear because ns1 is broken- my LB already removed it from the set
          my-website     A       91.219.150.30 ; fronted by a pair of CNAMEs due to loadbalancing but still
          my-website     AAAA    2a06:dd00:1:4::4189 ; same
          

          But even if I query 1.1.1.1 directly for my-website's record, it just doesn't work most of the time because the resolver pins itself to ns1 which is currently failing, or it selects ns1 and does not even care to try ns2.

          To be precise: some resolver implementations DO fall back to ns2 as expected, but most of them just pin themselves to ns1 and then outright refuse to resolve the records in my zone.

          And there's actually no reasonable way out, as far as I can see:

          • moving my DNS infra somewhere else (CloudFlare, for example) is unacceptable since I would like for my homelab to be as independent as practically possible;
          • anycasting, or running a fully-fledged BGP AS is also impossible because that costs a lot of money and I'd like for my homelab to fit into a $10/month budget with room to spare;
          • "live-patching" the NS and glue records in the parent zone (.network), to keep up with the set of my working nodes, is possible, but very unwieldy and somewhat hard to accomplish.

          There's a lot of custom machinery that keeps my workloads running and accessible after a node failure, but all of this becomes completely moot when authoritative DNS is the bottleneck.

          Has anyone been running a similar stack and encountered this problem? I'm aware that the answer is usually "host your DNS at CloudFlare" or "use the registrar's DNS infra" but still...

          1 Cevap Son cevap
          1

          Hello! It looks like you're interested in this conversation, but you don't have an account yet.

          Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

          With your input, this post could be even better 💗

          Kayıt Ol Giriş
          Cevap
          • Yeni başlık oluşturarak cevapla
          Cevaplamak için giriş yapın
          • En eskiden en yeniye
          • En yeniden en eskiye
          • En çok oylanan


            Önerilen Başlıklar

            • C

              Any good file sync server with web interface other than Nextcloud?

              Takip ediliyor Susturulmuş Konu Zamanlandı Sabitlendi Kilitli Taşındı Selfhosted selfhosted
              1
              1 Oy
              1 İleti
              0 Bakış
              Kimse yanıtlamadı
            • K

              [AIP] Portabase v1.29 - database configuration from the dashboard, MongoDB SRV support and file availability checks

              Takip ediliyor Susturulmuş Konu Zamanlandı Sabitlendi Kilitli Taşındı Selfhosted selfhosted
              1
              1
              1 Oy
              1 İleti
              0 Bakış
              Kimse yanıtlamadı
            • H

              My self-hosted experience - and my favorite container

              Takip ediliyor Susturulmuş Konu Zamanlandı Sabitlendi Kilitli Taşındı Selfhosted selfhosted
              1
              1 Oy
              1 İleti
              1 Bakış
              Kimse yanıtlamadı
            • D

              GitHub Has an Availability Problem. Is It Time to Look Elsewhere?

              Takip ediliyor Susturulmuş Konu Zamanlandı Sabitlendi Kilitli Taşındı Selfhosted selfhosted
              1
              1
              1 Oy
              1 İleti
              0 Bakış
              Kimse yanıtlamadı
            • E

              RSS Relay Explorer: A Streamlit tool to aggregate Hacker News, Reddit, and Lemmy with optional DeepL translation

              Takip ediliyor Susturulmuş Konu Zamanlandı Sabitlendi Kilitli Taşındı Selfhosted selfhosted
              1
              2
              1 Oy
              1 İleti
              1 Bakış
              Kimse yanıtlamadı

            Developed by Enes Uysal & Kadir Ay

            7

            Çevrimiçi

            8.8k

            Kullanıcı

            1.9k

            Konu

            3.7k

            İleti
            • Giriş

            • Hesabınız yok mu? Kayıt Ol

            • Aramak için giriş yapın veya kaydolun
            • İlk ileti
              Son ileti