Scoped credentials and policy for the PowerDNS API, e.g. ACME DNS-01 without the master key
4.3K
A policy-enforcing adapter for the PowerDNS Authoritative HTTP API. PowerDNS has a single static API key and no authorisation, so a key that can add a TXT record can also delete a zone or read DNSSEC private keys. pdns-api-cage holds the real key and never discloses it; each application (Traefik doing ACME DNS-01, a dynamic-DNS updater, a backup client) gets a scoped credential limited to the records its policy allows. The built-in acme preset grants only ACME challenge TXT records in the zones you list.
A single static Go binary on an otherwise empty scratch image (amd64 and arm64), running unprivileged with no capabilities and sandboxed with Landlock and seccomp. Releases are built from signed tags, signed with cosign and byte-reproducible. Pre-v1: expect breaking changes between minor releases. Pin to X.Y.Z, or follow X.Y, X or latest.
Content type
Image
Digest
sha256:ee84b98a2…
Size
3.5 MB
Last updated
9 days ago
docker pull grepular/pdns-api-cagePulls:
400
Sep 21 to Sep 27