Sign inSign up

osourcese/bind-dns

By osourcese

•Updated 4 months ago

Bind DNS server built with the purpose of running bind as a non root user.

Image
Networking
0

2.7K

osourcese/bind-dns repository overview

⁠Bind-DNS

Container with bind9 built with podman to ensure it works in rootless mode, works on other container platforms as well since it follows common practice.

The containers default mode is cache only with no forwarders to get it running.


⁠Persistent storage

The configuration and data resides in /etc/bind directory within the container, make sure to create a volume pointing to it if you want it to survive container upgrades and container migrations.

⁠Create

To create the container do like this, change latest to version number if you would like to run a specific version.

podman create --dns=127.0.0.1 \
--publish 5353:53/tcp --publish 5353:53/udp \
--name ContainerName--volume VolumeName:/etc/bind:Z \
docker.io/osourcese/bind-dns:latest

⁠Configuration

all tools like rndc, named-checkconf, named-checkzone works within the container and when doing a configuration / zone change i recommend you always run named-checkconf -z before doing a rndc reload or a restart of the container to catch configuration errors.

⁠Access

To edit configuration and zones connect to the container with the binddns user to ensure that correct permissions are intact.

During startup the permissions will be corrected if wrong but it is always better to avoid it from the start.

binddns user: podman exec -i -t -u binddns ContainerName /bin/bash

root user: podman exec -i -t -u 0 ContainerName /bin/bash

⁠Issues

⁠Configuration Errors

If the container wont start due to a error in configuration, check the container log for information about what is wrong and the insert a new configuration file like this, the default owner of the file will be root until the container starts, it will be changed to right permissions before bind9 actually starts.

Insert files with podman like this, work with every file like configurations, zones & keys.

podman cp ./named.conf.options ContainerName:/etc/bind/named.conf.options
podman cp ./named.conf.local ContainerName:/etc/bind/named.conf.local
⁠Ports

The container uses 5353 as default external port due to podman not allowing ports below 1024 in rootless and not all client can handle different port for DNS than port 53.

There are various ways of fixing this, one way it to edit system configuration to allow podman in rootless to access ports below 1024, but that is not a way i would recommend.

If you have iptables on your host like i have on Ubuntu, you can forward the port 53 internally to 5353 like this.

sudo iptables -t nat -I PREROUTING -p udp --dport 53 -j REDIRECT --to-ports 5353
sudo iptables -t nat -I OUTPUT -p udp -o lo --dport 53 -j REDIRECT --to-ports 5353
sudo iptables -t nat -I PREROUTING -p tcp --dport 53 -j REDIRECT --to-ports 5353
sudo iptables -t nat -I OUTPUT -p tcp -o lo --dport 53 -j REDIRECT --to-ports 5353
sudo apt install iptables-persistent

The package iptables-persistent makes it possible to save the rules and makes them persistent over reboots of host system, it will save all active rules during installation so that is the reason it is installed after we created the first set of rules. If you already are running iptables-persistent use the commands below instead to save the new rules to file.

The rules files resides under /etc/iptables and adding and removing is done with regular iptables command followed by below command to save them permanently.

To save new changes after this use the following commands depending on if you use IPv4 or IPv6.

sudo iptables-save
or
sudo ip6tables-save
⁠Default Forwarders

The container comes with the following DNS servers as forwarders since version 1.0.5 for easier testing.

8.8.8.8
1.1.1.1

If you block them on your local network just remember to change them to your providers DNS servers or allow the server running this container to access them.

⁠Versions

The latest will be updated with newest version available whenever possible and named versions will go back max 1 year, older than that will be removed.

⁠latest:
  • Image refresh
⁠1.0.6:
  • Image refresh
⁠1.0.5:
  • Image refresh
⁠1.0.4:
  • Image refresh
⁠1.0.3:
  • Image refresh
⁠1.0.2:
  • Image refresh
⁠1.0.1:
  • Image refresh
⁠1.0.0:
  • First initial release
  • Changed base image of Ubuntu from latest to rolling to get security fixes faster.

⁠More...

Visit my site for more stuff⁠ or on Twitter/X⁠

Tag summary

Content type

Image

Digest

sha256:ca2715a40…

Size

76.1 MB

Last updated

4 months ago

docker pull osourcese/bind-dns