Sign inSign up

grepular/pdns-api-cage

Sponsored OSS

By grepular

•Updated 9 days ago

Scoped credentials and policy for the PowerDNS API, e.g. ACME DNS-01 without the master key

Image
0

4.3K

grepular/pdns-api-cage repository overview

⁠pdns-api-cage

A policy-enforcing adapter for the PowerDNS Authoritative HTTP API. PowerDNS has a single static API key and no authorisation, so a key that can add a TXT record can also delete a zone or read DNSSEC private keys. pdns-api-cage holds the real key and never discloses it; each application (Traefik doing ACME DNS-01, a dynamic-DNS updater, a backup client) gets a scoped credential limited to the records its policy allows. The built-in acme preset grants only ACME challenge TXT records in the zones you list.

A single static Go binary on an otherwise empty scratch image (amd64 and arm64), running unprivileged with no capabilities and sandboxed with Landlock and seccomp. Releases are built from signed tags, signed with cosign and byte-reproducible. Pre-v1: expect breaking changes between minor releases. Pin to X.Y.Z, or follow X.Y, X or latest.


Hire me⁠ · Blog⁠ · RSS feed⁠

⁠Support/Appreciate my work

Tag summary

Content type

Image

Digest

sha256:ee84b98a2…

Size

3.5 MB

Last updated

9 days ago

docker pull grepular/pdns-api-cage

This week's pulls

Pulls:

400

Sep 21 to Sep 27