A CoreDNS Docker image with the RRL (Response Rate Limiting) plugin built-in. RRL provides BIND-like Response Rate Limiting to help mitigate DNS amplification attacks and allows request rate limiting.
latest - Latest stable release1.x.x - Specific CoreDNS version (e.g., 1.11.1)1.x.x-hash - Build with specific commit hash1.x.x-hash-timestamp - Full unique build tagMulti-platform: linux/amd64, linux/arm64
The RRL plugin tracks response rates per category of response and can drop responses when rates exceed configured thresholds. This helps protect your DNS infrastructure from:
docker run -d \
--name coredns-rrl \
-p 53:53/udp \
-p 53:53/tcp \
-v $(pwd)/Corefile:/Corefile \
prommits/coredns-rrl:latest
. {
rrl . {
responses-per-second 10
nxdomains-per-second 10
window 15
slip-ratio 2
}
forward . 8.8.8.8 8.8.4.4
log
errors
cache 30
}
| Option | Description | Default |
|---|---|---|
window | Rolling window in seconds | 15 |
ipv4-prefix-length | IPv4 prefix length for client identification | 24 |
ipv6-prefix-length | IPv6 prefix length for client identification | 56 |
responses-per-second | Positive responses allowed per second | 0 (disabled) |
nodata-per-second | NODATA responses allowed per second | (uses responses-per-second) |
nxdomains-per-second | NXDOMAIN responses allowed per second | (uses responses-per-second) |
referrals-per-second | Referral responses allowed per second | (uses responses-per-second) |
errors-per-second | Error responses allowed per second | (uses responses-per-second) |
slip-ratio | Every Nth dropped response slips through (truncated) | 0 (disabled) |
requests-per-second | Requests allowed per second | 0 (disabled) |
max-table-size | Maximum responses to track | 100000 |
report-only | Log metrics without dropping | false |
Content type
Image
Digest
sha256:d602ca5d6…
Size
25.2 MB
Last updated
7 months ago
docker pull prommits/coredns-rrl