Sign inSign up

bugfishtm/dnshttp

By bugfishtm

β€’Updated about 2 months ago

Bind9 Web Manager - Full-featured BIND9 web manager with master, slave, and hybrid DNS support.

Image
Networking
Developer tools
Web servers
0

3.6K

bugfishtm/dnshttp repository overview

⁠Bind9 Web Manager [DNSHTTP]

Warning

As of version 4.2.0, a new volume has been added to the docker-compose file. Please update your Docker configuration and container volumes accordingly to include the new volume (Dnshttp-keys).

Tip

No new features are currently planned for this project. However, users are welcome to create issues or feature requests, which will be reviewed and responded to within 1–3 weeks.

β πŸš€ Introduction

Bind9 Web Manager (DNSHTTP) is a web-based management interface for BIND9 DNS servers. It centralizes domain and record management, server replication, security controls, and operational insights into a single platform β€” making DNS administration more straightforward for both single-server setups and multi-server architectures.

DNSHTTP supports hybrid server configurations, where a single server acts as both a Master and a Slave simultaneously. This is useful for reducing infrastructure complexity while still maintaining proper replication across your DNS architecture.

To set up a hybrid environment, deploy the software on both servers. On the Master server, configure the Slave Server entry, and on the Slave server, configure the Master Server entry. Once both sides are configured, the servers can replicate with each other bidirectionally as needed.

DNSHTTP can operate as a dedicated DNS control panel alongside existing hosting panels such as Virtualmin, Plesk, ISPConfig, and others β€” managing your Bind9 DNS layer independently without interfering with your existing stackπŸ”Œ. In Docker environments, only the standalone deployment is supported, which is also the case when installing via the setup script .


⁠🐳 Docker

To deploy the Docker image bugfishtm/dnshttp:latest using a single command, you can use the following:

services:
  dnshttp:
    image: bugfishtm/dnshttp:latest
    restart: always
    ports:
      - "80:80/tcp"
      - "443:443/tcp"
      - "53:53/tcp"
      - "53:53/udp"
      - "953:953/tcp"
      - "953:953/udp"
      - "853:853/tcp"
    volumes:
      - dnshttp-ssl:/opt/sf_ssl
      - dnshttp-certbot:/etc/letsencrypt
      - dnshttp-data:/var/www/html/_data
      - dnshttp-keys:/etc/bind/dnshttp/keys
      - dnshttp-mysql:/var/lib/mysql
    environment:
      TZ:                                       "${sf_timezone}"     
      sf_ct_update_on_start:                    "${sf_ct_update_on_start}"  
      sf_timezone:                              "${sf_timezone}"
      sf_db_pass:                               "${sf_db_pass}"
      sf_url:                                   "${sf_url}"
      sf_secret:                                "${sf_secret}"    
      sf_letsencrypt_enable:                    "${sf_letsencrypt_enable}"
      sf_letsencrypt_domain:                    "${sf_letsencrypt_domain}"
      sf_letsencrypt_email:                     "${sf_letsencrypt_email}"
      sf_db_host:                               "${sf_db_host}"   
      sf_db_db:                                 "${sf_db_db}"   
      sf_db_user:                               "${sf_db_user}"   
      sf_db_port:                               "${sf_db_port}"   
      sf_db_prefix:                             "${sf_db_prefix}"   
      sf_cookie_prefix:                         "${sf_cookie_prefix}"   
      PHP_OPCACHE_ENABLE:                       "${APS_PHP_OPCACHE_ENABLE}"
      PHP_OPCACHE_MEMORY_CONSUMPTION:           "${APS_PHP_OPCACHE_MEMORY_CONSUMPTION}"
      PHP_OPCACHE_MAX_ACCELERATED_FILES:        "${APS_PHP_OPCACHE_MAX_ACCELERATED_FILES}"
      PHP_OPCACHE_VALIDATE_TIMESTAMPS:          "${APS_PHP_OPCACHE_VALIDATE_TIMESTAMPS}"
      PHP_OPCACHE_JIT:                          "${APS_PHP_OPCACHE_JIT}"
      PHP_OPCACHE_JIT_BUFFER_SIZE:              "${APS_PHP_OPCACHE_JIT_BUFFER_SIZE}"
      PHP_ZLIB_OUTPUT_COMPRESSION:              "${APS_PHP_ZLIB_OUTPUT_COMPRESSION}"
      PHP_OUTPUT_BUFFERING:                     "${APS_PHP_OUTPUT_BUFFERING}"
      PHP_FPM_PM:                               "${APS_PHP_FPM_PM}"
      PHP_FPM_PM_MAX_CHILDREN:                  "${APS_PHP_FPM_PM_MAX_CHILDREN}"
      PHP_FPM_PM_START_SERVERS:                 "${APS_PHP_FPM_PM_START_SERVERS}"
      PHP_FPM_PM_MIN_SPARE_SERVERS:             "${APS_PHP_FPM_PM_MIN_SPARE_SERVERS}"
      PHP_FPM_PM_MAX_SPARE_SERVERS:             "${APS_PHP_FPM_PM_MAX_SPARE_SERVERS}"
      PHP_FPM_PM_MAX_REQUESTS:                  "${APS_PHP_FPM_PM_MAX_REQUESTS}"    
      MYSQL_INNODB_BUFFER_POOL_SIZE:             "${APS_MYSQL_SETUP_BUFFER_POOL_SIZE}"
      APS_MYSQL_TABLE_OPEN_CACHE:                "${APS_MYSQL_TABLE_OPEN_CACHE}"
      APS_MYSQL_SETUP_BUFFER_POOL_INSTANCES:     "${APS_MYSQL_SETUP_BUFFER_POOL_INSTANCES}"
      APS_MYSQL_SETUP_LOG_SIZE:                  "${APS_MYSQL_SETUP_LOG_SIZE}"
      APS_MYSQL_MAX_CONN:                        "${APS_MYSQL_MAX_CONN}"
      APS_MYSQL_FLUSH_TRX_COMMIT:                "${APS_MYSQL_FLUSH_TRX_COMMIT}"
      APS_MYSQL_CAPACITY:                        "${APS_MYSQL_CAPACITY}"  
volumes:
  dnshttp-ssl:
  dnshttp-certbot:
  dnshttp-mysql:
  dnshttp-data:
  dnshttp-keys:

⁠🧩 Variables
##
## DNSHTTP Docker Env Variable File
##

##
## Time Zone Setup
## Set up Timezone like example: Europe/Berlin
## Use tz identifiers from https://en.wikipedia.org/wiki/List_of_tz_database_time_zones
##
sf_timezone="Europe/Berlin"

##
## Database Password for Root Account
## Do not only use following signs:
## A-Z a-z 0-1 ! = ?
##
sf_db_pass="secret_mysql_password"

##
## Secret Key Configuration
## This key is required to encrypt DNSHTTP data.  
## Changing the key while the instance is running will make existing  
## encrypted data inaccessible. Keep this key safe and never lose it!
## Do not use more than 32 Signs.
##  
sf_secret="generate_your_secret_key"

##
## Public URL where this website will be visible on.
## DNSHTTP may not depend on this setting and will use auto-fetched current site url.
## So get sure to set up your reverse proxy to get a valid connection.
## Can be HTTP/HTTPS URL, DNSHTTP should not be installed in a websites sub-folder.
##
sf_url="http://localhost"

##
## Let's Encrypt Settings
## Enable or disable automatic Let's Encrypt SSL certificate issuance.
## - sf_letsencrypt_enable: Set to 1 to enable, 0 to disable.
## - sf_letsencrypt_domain: The domain name to issue the certificate for.
## - sf_letsencrypt_email: Email address for Let's Encrypt registration and notifications.
##
sf_letsencrypt_enable=0
sf_letsencrypt_domain="localhost"
sf_letsencrypt_email="localhost@localhost"

##
## Database Details for Connection
## Leave as it is, do only change if you know what you are doing!
## Currently you cannot change the port, its always 3306
## Let me know on github when you need it changed, i will implement.
##
sf_db_host="127.0.0.1"
sf_db_db="dnshttp"
sf_db_user="root"
sf_db_prefix="sf_"
sf_db_port=3306

##
## DNSHTTP Cookie Prefix
## Do not change unless you know what you are doing.
##
sf_cookie_prefix="sf_"

##
## Container upgrade settings
## Controls whether the container should automatically update and upgrade packages each time it starts.
## 1 = enable automatic updates/upgrades on startup
## 0 = skip update/upgrade steps on startup for faster boot
##
sf_ct_update_on_start=0

##
## Settings for MySQL Environment
##
APS_MYSQL_SETUP_BUFFER_POOL_SIZE=2G
APS_MYSQL_SETUP_BUFFER_POOL_INSTANCES=8
APS_MYSQL_SETUP_LOG_SIZE=256M
APS_MYSQL_MAX_CONN=200    
APS_MYSQL_FLUSH_TRX_COMMIT=2    
APS_MYSQL_CAPACITY=2000    
APS_MYSQL_TABLE_OPEN_CACHE=4000   

##
## Settings for PHP Environment
##
APS_PHP_OUTPUT_BUFFERING=4096
APS_PHP_ZLIB_OUTPUT_COMPRESSION=1
APS_PHP_OPCACHE_ENABLE=1
APS_PHP_OPCACHE_MEMORY_CONSUMPTION=512
APS_PHP_OPCACHE_MAX_ACCELERATED_FILES=20000
APS_PHP_OPCACHE_VALIDATE_TIMESTAMPS=0
APS_PHP_OPCACHE_JIT=tracing
APS_PHP_OPCACHE_JIT_BUFFER_SIZE=100M
APS_PHP_FPM_PM=dynamic
APS_PHP_FPM_PM_MAX_CHILDREN=50      
APS_PHP_FPM_PM_START_SERVERS=10
APS_PHP_FPM_PM_MIN_SPARE_SERVERS=5
APS_PHP_FPM_PM_MAX_SPARE_SERVERS=20
APS_PHP_FPM_PM_MAX_REQUESTS=1000
β πŸ“¦ Volumes
VolumeDescriptionPath on Container
dnshttp-certbotStores persistent certbot data./etc/letsencrypt
dnshttp-sslStores persistent ssl data./opt/sf_ssl
dnshttp-mysqlStores persistent mysql database data./var/lib/mysql
dnshttp-dataStores persistent website data./var/www/html/_data
dnshttp-keysDNSSEC Key Material./etc/bind/dnshttp/keys
β πŸ”Œ Ports
PortDescription
80Port for HTTP Connections to website.
443Port for HTTPS Connections to website.
53DNS Related.
853DNS Related.
953DNS Related.

⁠πŸ”₯ Features

Delivers the essential tools to effectively manage your site’s content, structure, and user rolesβ€”streamlined for simplicity, without unnecessary complexity. For a broad overview of its capabilities, refer to the feature list below.

β πŸ“‹ Domain and Record Management

The core of DNSHTTP is its domain and DNS record management. You can add, edit, and remove domains along with all of their associated DNS records directly through the web interface, without manually editing zone files or reloading services by hand.

β πŸ›‘οΈ Access Control

The software features a robust user and group management system, enabling administrators to efficiently create, organize, and manage both users and user groups. With flexible permission controls, administrators can assign specific access rights to groups and individual users, ensuring secure and streamlined management of user privileges across the platform.

β πŸ”„ Slave Server Replication

DNSHTTP gives you direct control over the replication process between your Master and Slave DNS servers, with real-time status updates so you can monitor the state of your replication at a glance.

  • The Domains Section displays both replicated slave domains and locally mastered domains side by side.
  • Conflicts occur when the same domain exists as both a master and a slave entry. These are automatically detected, clearly highlighted, and can be resolved through the dedicated Conflicts section.
⁠🚫 IP Blacklisting

DNSHTTP includes built-in IP blacklisting to help protect your DNS infrastructure from suspicious or unauthorized activity. When a threat is identified, the offending IP can be banned directly through the interface. Bans can be lifted manually at any time, or you can set up the blacklist.php cronjob to automate blacklisting resets on a scheduled basis.

β πŸ“Š Replication Insights

Beyond basic replication controls, DNSHTTP provides detailed insights into the state of your replication and domain configuration. This gives you the visibility needed to make informed decisions, catch issues early, and proactively manage your DNS replication strategy across all connected servers.

β πŸ”Œ External API

DNSHTTP exposes an API interface secured with tokens, allowing external systems and scripts to perform DNS operations programmatically. This makes it straightforward to integrate DNS management into your existing workflows, automation pipelines, or third-party tooling.

⁠πŸ–₯️ Integrated Installer

The installation process is simplified through a clear and intuitive graphical user interface (GUI), making setup quick and accessible for users with minimal technical experience. Additionally, advanced users can choose from alternative installation methods such as Docker containers or automated scripts, providing flexible deployment options to suit different environments and preferences.


β πŸ—’οΈ Requirements

Below are the requirements for the webserver. Additional default installed linux and php modules are required as openssl and more, usually they are already installed by default and so not listed here.

RequirementMinimum ValueRecommended Value
Server Root AccessRequired-
Linux Package: bind9Required-
Linux Package: cronRequired-
Linux Package: bind9-utilsRequired-
Linux Package: dnsutilsRequired-
Linux Package: php8.2(+)Required-
Apache2 Module: headersRequired-
Apache2 Module: rewriteRequired-
PHP Memory Limit128M256M
PHP Max Post Size128M256M
PHP Max Execution Time180s600s
PHP Module: MySQLiEnabled-
PHP Module: JSONEnabled-
PHP Module: mbstringEnabled-
PHP Module: cURLEnabled-
PHP Module: intlEnabled-
PHP Module: sessionEnabled-

β πŸ› οΈ Installation

You can see detailed information at the installation documentation page at: https://bugfishtm.github.io/Bind9-Web-Manager/installation.html⁠. Choose the method that best fits your hosting environment and needs.

The initial user account created for the website during installation serves as the primary administrator. This account has full access to configure and manage the system. It is important to secure this account by updating its credentials promptly after installation to protect the site from unauthorized access.

🧍 Initial username: admin πŸ”‘ Initial password: changeme

Consider setting up additional user accounts with appropriate roles and permissions to ensure proper administration and security management going forward.

β βœ‹ Manual

⚠️ It is highly recommended to change the admin password immediately after installation.

Installing the Bind9 Web Manager is straightforward. For detailed instructions on manual installation, please refer to the documentation located in the index.html file within the repository's docs folder, or visit https://bugfishtm.github.io/Bind9-Web-Manager/installation_manual.html⁠.

⁠🐳 Docker

⚠️ It is highly recommended to change the admin password immediately after installation.

This method installs the standalone version of DNSHTTP. This ensures a secure and isolated installation suitable for most web use cases. For Docker installation, visit: https://hub.docker.com/r/bugfishtm/dnshttp⁠.

β πŸ“„ Script

⚠️ It is highly recommended to change the admin password immediately after installation.

This script is intended for use only on freshly installed servers. In the github repository's _scripts folder, you'll find an installation script designed to install the full version with all features on a dedicated server. Execute the following Commands and navigate through the installation shell process to install DNSHTTP.

curl -o ./installer.sh https://raw.githubusercontent.com/bugfishtm/Bind9-Web-Manager/refs/heads/main/_scripts/installer.sh
chmod u+x ./installer.sh  
sh ./installer.sh install

This script is intended for users who wish to utilize standalone functionality on a fresh system.


β πŸ“– Documentation

The following documentation is intended for both end-users and developers.

DescriptionLinkScope
DNSHTTP Tutorial Videoshttps://www.youtube.com/playlist?list=PL6npOHuBGrpChSvani3MESZnzuKwwxz4o⁠Developers/Users
DNSHTTP Documentationhttps://bugfishtm.github.io/Bind9-Web-Manager/⁠Developers/Users
Bugfish Framework Documentationhttps://bugfishtm.github.io/Bind9-Web-Manager/extra-framework/⁠Developers

Relevant github repositories related to Bind9 Web Manager.

DescriptionLinkScope
Bind9 Web Managerhttps://github.com/bugfishtm/Bind9-Web-Manager⁠Developers
Bugfish Frameworkhttps://github.com/bugfishtm/bugfish-framework⁠Developers

Relevant docker repositories related to Bind9 Web Manager.

DescriptionLinkScope
DNSHTTP Docker Imagehttps://hub.docker.com/r/bugfishtm/dnshttp⁠Users

β πŸ“ Repository Structure

This table provides an overview of key files and folders related to the repository. Click on the links to access each file for more detailed information. If certain folders are missing from the repository, they are irrelevant to this project.

Document TypeDescription
.git/Internal file, that can be ignored.
.github/Internal file, that can be ignored.
.github/CODE_OF_CONDUCT.md⁠community guidelines for participation.
_archive/Folder for storing archived or deprecated files.
_changelogs/Folder containing changelogs for version tracking.
_configuration/Settings.php configuration examples for different environments.
_docker/Folder with Docker-related files for building images.
_images/Folder containing project images and graphics.
_licenses/Folder with third-party license information.
_releases/Folder containing release versions of the project.
_screenshots/Folder with screenshots of the project.
_scripts/Folder for additional scripts and utilities.
_source/Folder containing the main source code.
_videos/Folder with project-related videos.
docs/Folder for documentation and guides.
.gitattributesInternal file, that can be ignored.
.gitignoreInternal file, that can be ignored.
repository_reset.batInternal file, that can be ignored.
repository_update.batInternal file, that can be ignored.
CHANGELOG.md⁠Internal file, that can be ignored.
CONTRIBUTING.md⁠contributors instruction file.
SECURITY.md⁠security and warranty file.
LICENSE.md⁠license file.
README.md⁠readme file.

β πŸ’¬ Support Channels

If you encounter any issues or have questions while using this software, feel free to contact us:


β πŸ“’ Spread the Word

Help us grow by sharing this project with others! You can:

  • Tweet about it – Share your thoughts on Twitter/X⁠ and link us!
  • Post on LinkedIn – Let your professional network know about this project on LinkedIn⁠.
  • Share on Reddit – Talk about it in relevant subreddits like r/programming⁠ or r/opensource⁠.
  • Tell Your Community – Spread the word in Discord servers, Slack groups, and forums.

β πŸ“‘ Changelog Information

Refer to the _changelogs folder for detailed HTML changelogs tracking updates across versions. These changelogs are also included in GitHub Releases for easy access.


⁠🌱 Contributing to the Project

Thank you for your interest in this project.

At this time, this repository is not open for external contributions.
Please do not submit pull requests or patches.

  • Pull requests from external contributors are not accepted.
  • Any unsolicited pull requests will be closed without review.
  • All code in this repository is maintained by the project owner.
  • By design, no third‑party code will be merged into this project via GitHub.

If you encounter a bug or have an enhancement suggestion, please check the "Issues" section of our GitHub repository or visit our official website for guidance before beginning any work on it.


⁠🀝 Community Guidelines

We’re focused on developing innovative solutions and advancing technology. By being part of this, you contribute to our progress.

Positive guidelines include being kind, empathetic, and respectful in all interactions. It is important to engage thoughtfully and offer constructive, solution-oriented feedback. Fostering an environment of collaboration, support, and mutual respect is essential.

Unacceptable behaviors include harassment, hate speech, or offensive language. Personal attacks, discrimination, or any form of bullying are not tolerated. Sharing private or sensitive information without explicit consent is strictly prohibited.

Together, we can partner to achieve common goals by following guidelines designed to promote effective collaboration and positive teamwork.


β πŸ›‘οΈ Security Policy

I take security seriously and appreciate responsible disclosure. If you discover a vulnerability, please follow these steps:

  • Do not report it via public GitHub issues or discussions. Instead, please contact the [email protected]⁠ email address directly.
  • Provide as much detail as possible, including a description of the issue, steps to reproduce it, and its potential impact.

I aim to acknowledge reports within 2–4 weeks and will update you on our progress once the issue is verified and addressed.

This software is provided as-is, without any guarantees of security, reliability, or fitness for any particular purpose. We do not take responsibility for any damage, data loss, security breaches, or other issues that may arise from using this software. By using this software, you agree that We are not liable for any direct, indirect, incidental, or consequential damages. Use it at your own risk.


β πŸ“œ License Information

The license for this software can be found in the LICENSE.md⁠ file. Third-party licenses are located in the ./_licenses folder. The software may also include additional licensed software or libraries.

🐟 Bugfish

Tag summary

Content type

Image

Digest

sha256:501425627…

Size

481 MB

Last updated

about 2 months ago

docker pull bugfishtm/dnshttp