dnsdist With An ACL, A Rate Limit And A Cache

dnsdist from EPEL, whose own unit cannot read the config the package installs; the role fixes the ownership, adds an ACL, a per-client query limit and a packet cache, stops the security poll, and keys the console. The live test sees a client outside the ACL dropped, a 100-query burst cut to 20, and a wrong console key refused. Original role, live-tested on Rocky Linux 10.

Verification

Live-tested

Really deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.

Conformance

  • Static validation (yamllint · ansible-lint)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-10-03 · podman 4.9.3 · ansible 2.21.4 · how we verify

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/ansible-dnsdist/badge)](https://www.iac-bazaar.com/catalog/ansible-dnsdist?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Ansible role 1.0.0, live-tested on IaC Bazaar: [dnsdist With An ACL, A Rate Limit And A Cache](https://www.iac-bazaar.com/catalog/ansible-dnsdist?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```yaml
# dnsdist With An ACL, A Rate Limit And A Cache: https://www.iac-bazaar.com/catalog/ansible-dnsdist (download from your IaC Bazaar account)
```

Preview:IaC Bazaar: live-tested

Documentation

dnsdist

dnsdist from EPEL: a DNS load balancer on loopback in front of the resolvers you list, with an ACL, a per-client query rate limit, a packet cache, no security poll to PowerDNS, and the console on loopback behind a key generated on the host. Original role for EL 10, live-tested with podman on Rocky Linux 10.

No download, and no version to pin. EL 10 packages dnsdist in EPEL, so the role installs it by name and takes what the distribution ships: a security update arrives through dnf, not through a new release of this role. What the role owns is the configuration and the proof that the service works.

The package's own service does not start. EPEL's unit runs as the dnsdist user and checks the configuration in ExecStartPre, but the package installs dnsdist.conf as root:root 0640 - unreadable to that user - so the stock service loops on "Unable to read configuration file" (measured). The role writes it root:dnsdist 0640. The unit keeps CAP_NET_BIND_SERVICE, which is how it listens on 127.0.0.1:53.

Proven by queries. The live test resolves a name through dnsdist, repeats it for the packet cache (cache hits counted), sees a query from 127.0.0.2 - outside the ACL - dropped without an answer, sends a burst of 100 queries from one address and gets at most 30 answered while a query two seconds later is answered again, and reads the security status as 0 with no "security status" line in the log. Both are needed: a poll logs such a line whether it succeeds ("Polled security status ... OK") or fails, and showSecurityStatus() reads 1 after a successful one (both measured).

A console that exits 0 when it refuses you. The console client takes its key from setKey in its own configuration and ignores -k; given a wrong key, it prints "The server closed the connection right away, likely indicating a key mismatch" and exits 0 (measured). The live test asserts that message, and the backends listed by a client holding the right key.

License

Commercial - IaC Bazaar EULA. (c) IaC Bazaar.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Variables
  • Test

Related modules

Live-tested

ansible-unbound-resolver

Unbound on loopback: DNSSEC validated locally against the root anchor, query names minimised, version hidden, and upstream over DNS-over-TLS by default because many networks reset TCP 53 to anything but a known resolver, which breaks full recursion the moment a DNSKEY answer outgrows UDP. Recursion is one setting away. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-bind-authoritative

BIND as an authoritative-only server. The package is a loopback resolver; add a zone and anyone who can query can copy the whole zone, and version.bind names the 9.18 to attack. This role turns recursion off, refuses transfers to anyone not listed, hides the identity records, rate-limits responses, and renders zones from data checked before they land. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-coredns

CoreDNS from the upstream release (sha256-verified) as a hardened system service answering authoritatively for your zones on 127.0.0.1:53 as a system user (CAP_NET_BIND_SERVICE through the unit), forwarding only when you name upstreams. The live test digs the example zone's A record with the aa flag, an NXDOMAIN in the zone and a REFUSED outside it. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-nsd

NSD from EPEL: an authoritative-only server for your zones, the configuration and every zone checked by NSD's own tools first, transfers only to the addresses and TSIG keys you name, response rate limiting, and the state directory the package leaves unwritable fixed. The live test gets the zone with the key and is refused without it. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-powerdns

PowerDNS authoritative from EPEL with its SQLite backend; the live test adds a zone through the API, gets the record from dig and NXDOMAIN for an unknown name, sees the API refuse a caller with no key, and reads the query counter. The schema is recovered when a docs-stripped host lacks it. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-bind-exporter

bind_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test brings up named with one zone and a statistics channel on loopback as a fixture, asks it a name with dig, and reads bind_up 1 and the A query counted. Original role, live-tested on Rocky Linux 10.

View module