Sign inSign up

prommits/coredns-rrl

By prommits

•Updated 7 months ago

Image
0

1.6K

prommits/coredns-rrl repository overview

⁠CoreDNS with Response Rate Limiting (RRL)

A CoreDNS Docker image with the RRL (Response Rate Limiting) plugin built-in. RRL provides BIND-like Response Rate Limiting to help mitigate DNS amplification attacks and allows request rate limiting.

⁠Resources

⁠Tags

  • latest - Latest stable release
  • 1.x.x - Specific CoreDNS version (e.g., 1.11.1)
  • 1.x.x-hash - Build with specific commit hash
  • 1.x.x-hash-timestamp - Full unique build tag

Multi-platform: linux/amd64, linux/arm64

⁠What is RRL?

The RRL plugin tracks response rates per category of response and can drop responses when rates exceed configured thresholds. This helps protect your DNS infrastructure from:

  • DNS amplification attacks
  • Reflection attacks
  • DDoS attacks targeting your DNS servers

⁠Quick Start

docker run -d \
  --name coredns-rrl \
  -p 53:53/udp \
  -p 53:53/tcp \
  -v $(pwd)/Corefile:/Corefile \
  prommits/coredns-rrl:latest

⁠Example Corefile

. {
  rrl . {
    responses-per-second 10
    nxdomains-per-second 10
    window 15
    slip-ratio 2
  }
  forward . 8.8.8.8 8.8.4.4
  log
  errors
  cache 30
}

⁠Configuration Options

OptionDescriptionDefault
windowRolling window in seconds15
ipv4-prefix-lengthIPv4 prefix length for client identification24
ipv6-prefix-lengthIPv6 prefix length for client identification56
responses-per-secondPositive responses allowed per second0 (disabled)
nodata-per-secondNODATA responses allowed per second(uses responses-per-second)
nxdomains-per-secondNXDOMAIN responses allowed per second(uses responses-per-second)
referrals-per-secondReferral responses allowed per second(uses responses-per-second)
errors-per-secondError responses allowed per second(uses responses-per-second)
slip-ratioEvery Nth dropped response slips through (truncated)0 (disabled)
requests-per-secondRequests allowed per second0 (disabled)
max-table-sizeMaximum responses to track100000
report-onlyLog metrics without droppingfalse

Tag summary

Content type

Image

Digest

sha256:d602ca5d6…

Size

25.2 MB

Last updated

7 months ago

docker pull prommits/coredns-rrl