Sign inSign up

gkweb76/unbound

By gkweb76

•Updated over 8 years ago

Unbound container based on Alpine Linux and LibreSSL.

Image
0

980

gkweb76/unbound repository overview

⁠Supported tags

⁠What is Unbound

Unbound⁠ is a caching DNS resolver that can be used on its own, or coupled with DNSCrypt proxy to have both a DNS caching service and encrypted DNS requests.

⁠Why using this image ?

This image is a vanilla Unbound software without any additional packages installed. This enables you to run it on its own or concurrently with the DNS encrypting service of your choice (e.g DNSCrypt proxy).

This image is based on Alpine Linux⁠ and therefore is built with LibreSSL⁠, which is a more secure fork of OpenSSL made by the OpenBSD⁠ team. Also Alpine Linux is generally immune to vulnerabilities targetting components not installed in this Operating System, such as: bash (e.g. Shellshock vulnerability), OpenSSL (e.g. Heartbleed vulnerability), glibc (e.g Ghost vulnerability). Also, Alpine Linux has a much smaller image size compared to other OS thanks to less packages installed by default and not relying on glibc, providing faster image download, and reduced attack surface, hence better security.

⁠Maintained by

Guillaume Kaddouch
Blog: https://networkfilter.blogspot.com/⁠
Twitter: @gkweb76⁠
Github: gkweb76⁠

⁠How to use this image from command line

First start unbound to make it create your unbound volume:
sudo docker run --rm --name unbound_setup -v unbound:/etc/unbound -p 53:53 gkweb76/unbound
docker volume inspect unbound | grep Mount
Grab the host real path, for instance /var/lib/docker/volumes/unbound/_data (referred as '$UNBOUND_VOLUME_PATH' below)

Then copy your files there, using the correct path:
cp ./unbound.conf $UNBOUND_VOLUME_PATH

Apply a strict chmod so that only root can modify these files:
chmod 644 $UNBOUND_VOLUME_PATH/unbound.conf

Start your container:
sudo docker run --rm --name unbound -v unbound:/etc/unbound --read-only=true \
-p 53:53 gkweb76/unbound

⁠Docker compose example

version: "3.5"

services:
   unbound:
     image: gkweb76/unbound:latest
     container_name: unbound
     read_only: yes
     ports:
       - "53:53/udp"
       - "53:53/tcp"
     networks:
       - unbound
     volumes:
       - unbound:/etc/unbound # stored as /var/lib/docker/volumes/<project_name>_unbound
       - /etc/localtime:/etc/localtime:ro # keep container clock in sync with host
     restart: "unless-stopped"

# Networks declaration
networks:
   unbound:

If you need help with your compose file, check the official documentation⁠.

⁠Tested on

Ubuntu⁠ 18.04 LTS and Docker 18.04.0 CE (Community Edition).

⁠License

MIT License

Tag summary

Content type

Image

Digest

Size

4 MB

Last updated

over 8 years ago

docker pull gkweb76/unbound