Sign inSign up

bigbeartechworld/big-bear-unbound

By bigbeartechworld

•Updated 12 days ago

Image
0

4.9K

bigbeartechworld/big-bear-unbound repository overview

⁠BigBear Unbound DNS Resolver

A privacy-focused, validating, recursive, caching DNS resolver Docker image based on NLnet Labs Unbound⁠.

⁠Features

  • ✅ Full Recursive Resolution - Acts as your own DNS resolver, querying root servers directly
  • ✅ DNSSEC Validation - Validates DNS responses to prevent DNS spoofing attacks
  • ✅ Privacy Focused - QNAME minimization reduces data leaked to DNS servers
  • ✅ Security Hardened - Includes protections against DNSBomb, CAMP, CacheFlush, and other attacks
  • ✅ Multi-Architecture - Supports amd64, arm64, and arm/v7
  • ✅ Non-Root - Runs as unprivileged user for enhanced security
  • ✅ Health Checks - Built-in health monitoring for container orchestration
  • ✅ Auto-Updated - Weekly checks for new Unbound releases

⁠Quick Start

version: '3'
services:
  unbound:
    image: bigbeartechworld/big-bear-unbound:latest
    container_name: unbound
    ports:
      - "53:53/udp"
      - "53:53/tcp"
    volumes:
      # Optional: Mount custom config
      - ./unbound.conf:/etc/unbound/unbound.conf:ro
    restart: unless-stopped
    # Optional: Use host networking for better performance
    # network_mode: host
⁠Docker Run
docker run -d \
  --name unbound \
  -p 53:53/udp \
  -p 53:53/tcp \
  --restart unless-stopped \
  bigbeartechworld/big-bear-unbound:latest

⁠Testing Your Resolver

# Test DNS resolution
dig example.com @localhost

# Test DNSSEC validation
dig +dnssec nlnetlabs.nl @localhost

# Verify DNSSEC is working (should show "ad" flag for authenticated data)
dig +dnssec +short example.com @localhost

⁠Configuration

⁠Custom Configuration

Mount your own unbound.conf to override the default configuration:

volumes:
  - /path/to/your/unbound.conf:/etc/unbound/unbound.conf:ro
⁠Important Configuration Options

The default configuration includes:

OptionDefaultDescription
qname-minimisationyesPrivacy: Sends minimal query info
aggressive-nsecyesPerformance: Reduces queries using NSEC
prefetchyesPerformance: Pre-fetches expiring entries
serve-expiredyesReliability: Serves stale data while refreshing
harden-*yesSecurity: Various hardening options
cache-min-ttl300Cache minimum 5 minutes
cache-max-ttl86400Cache maximum 24 hours
⁠Forwarding Mode (Optional)

To use DNS-over-TLS forwarding instead of recursive resolution, uncomment the forward-zone section in unbound.conf:

forward-zone:
    name: "."
    forward-tls-upstream: yes
    forward-addr: 1.1.1.1@853#cloudflare-dns.com
    forward-addr: 1.0.0.1@853#cloudflare-dns.com

⁠CasaOS Integration

For CasaOS users, use this docker-compose configuration:

version: '3'
services:
  unbound:
    image: bigbeartechworld/big-bear-unbound:latest
    container_name: big-bear-unbound
    ports:
      - "5353:53/udp"
      - "5353:53/tcp"
    volumes:
      - /DATA/AppData/big-bear-unbound/conf:/etc/unbound:ro
    restart: unless-stopped

Note: Using port 5353 to avoid conflict with system DNS. Configure your devices to use port 5353 or set up port forwarding.

⁠Network Configuration

⁠Using as Network-Wide DNS
  1. Set your router's DHCP server to advertise this container's IP as the DNS server
  2. Or configure individual devices to use this resolver
⁠Pi-hole Integration

Use Unbound as upstream DNS for Pi-hole:

# In Pi-hole, set custom upstream DNS:
# Use the Docker network IP of your Unbound container, e.g.:
172.17.0.2#53

⁠Security Considerations

  • Access Control: By default, accepts queries from all IPs. Restrict access-control in production.
  • Non-Root: Runs as the unbound user, not root
  • DNSSEC: Validates DNS responses by default
  • Attack Mitigations: Includes protections against:
    • DNSBomb (CVE-2024-33655)
    • CAMP amplification attacks
    • CacheFlush attacks
    • DNS cache poisoning

⁠Troubleshooting

⁠Check Container Logs
docker logs unbound
⁠Test Configuration
docker exec unbound unbound-checkconf /etc/unbound/unbound.conf
⁠Common Issues
  1. Port 53 already in use: Stop systemd-resolved or use a different port

    sudo systemctl stop systemd-resolved
    
  2. Permission denied: Ensure mounted volumes are readable by UID 101 (unbound user)

  3. DNSSEC failures: Check if your system clock is accurate

⁠License

This Docker image configuration is provided under the MIT License. Unbound itself is licensed under the BSD License.

Tag summary

Content type

Image

Digest

sha256:9bf13bb06…

Size

57.6 MB

Last updated

12 days ago

docker pull bigbeartechworld/big-bear-unbound