fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

9.9K
active users

#dnsdist

1 post1 participant0 posts today
I'm not sure whether I'm holding ChatGPT wrong. Whenever someone convinces me to give it another try, I ask something along the line "Generate a config file for X so that is does Y and Z". ChatGPT spits out a configuration with undocumented options. I ask back for a source for the used options. ChatGPT tells me that I'm right and those options do not exist and spits out an alternative config which is correct but completely misses the point of the original question... Then I don't use it again for a few month until another colleague tells me it got a lot better now. #ai #dnsdist config....

Ugh, Turns out letting your #dns server mirror the root zone is a good way to amplify ddos attacks...

Added a rule to #dnsdist that drops incoming packets with RD set while I come up with something more elegant.

The victim seems to be a small Brazilian ISP Jupiter. :(

The DNS-collector v0.44.0 is available! The focus of this update is on maintenance to prepare future stable release
- Fixed support for IP fragments with AFPACKET sniffer.
- Major code refactoring of the base code.
- Completely redesigned the configuration checker.

github.com/dmachard/go-dnscoll

GitHubRelease v0.44.0 · dmachard/go-dnscollectorWhat's Changed If you find the project helpful, please consider supporting the project via monthly donation via GitHub Sponsors or simply add a star to this project. Highlights The focus of this up...
Replied in thread

@pemensik

That what I did understood by reading the doc.

#PowerDNS's #DNSDist seems a superb project, just maybe a bit overhelm for what it should do in this specific case. Yet seems likely the only option, actually.

It's a bit of a shame no other #DoH #CGI have been written in compiled languages so far... which is likely why few resolver support such forwarding.

When I first read about DNS-over-HTTP, I saw it as a further centralization attempt by #Google & friends (which sadly includes @mozilla these days), since to get a working DoH service you need good sysadmin skills and a stable public IP: not something a kid with a cheap shared hosting can set up.

And ə PHP implementation would be too slow.

#FossilSCM made me realize that a simple CGI in C could have good performances and be widely distributed, so I wrote one (still early alpha).

Now I can use it in most (non enterprise managed¹) browser, but I'd like to try it system wide.

Anyway... thanks for your help guys!

@draeath

Replied in thread

@tuhgy I use netdata agents to expose prometheus metrics and then graph that with grafana. I'm using this dns load balancer called #dnsdist and that exposes prometheus metrics that I scrape and gives me all of the DNS stuff. I balance 2 dns servers with it.

The DNS-collector v0.42.0 is now available! This release introduces some important bug fixes (memory leak) and minor features.
- Fix memory leak with ElasticSearch logger, thank to @misaki-kawakami to report that.
- Optimizations to reduce CPU usage, more particularly for flat-json
- Add support for query-zone field on DNStap collector

github.com/dmachard/go-dnscoll

GitHubRelease v0.42.0 · dmachard/go-dnscollectorIf you find the project helpful, please consider supporting the project via monthly donation via GitHub Sponsors or simply add a star to this project. Highlights This release introduces some import...