dnsmasq That Keeps Private Names Home And Drops Rebinding Answers

dnsmasq from AppStream answering your local names and caching the rest: bound only to the addresses you name, plain names and private reverse lookups kept on the host, upstream answers pointing at private addresses dropped, DNSSEC validated. The live test reads dnsmasq's own upstream counters to prove what was not forwarded. Original role, live-tested on Rocky Linux 10.

Verification

Live-tested

Really deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.

Conformance

  • Static validation (yamllint · ansible-lint)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-10-08 · podman 4.9.3 · ansible 2.21.4 · how we verify

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/ansible-dnsmasq/badge)](https://www.iac-bazaar.com/catalog/ansible-dnsmasq?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Ansible role 1.0.0, live-tested on IaC Bazaar: [dnsmasq That Keeps Private Names Home And Drops Rebinding Answers](https://www.iac-bazaar.com/catalog/ansible-dnsmasq?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```yaml
# dnsmasq That Keeps Private Names Home And Drops Rebinding Answers: https://www.iac-bazaar.com/catalog/ansible-dnsmasq (download from your IaC Bazaar account)
```

Preview:IaC Bazaar: live-tested

Documentation

dnsmasq

dnsmasq from AppStream answering your local names and caching everything else: bound only to the addresses you name, plain names and private reverse lookups kept on the host, upstream answers that point a public name at a private address dropped, and DNSSEC validated. Original role for EL 10, live-tested with podman on Rocky Linux 10.

No download, and no version to pin. EL 10 packages dnsmasq, so the role installs it by name and takes what the distribution ships: a security update arrives through dnf, not through a new release of this role. What the role owns is the configuration and the proof that the service works.

The distribution's unit, our configuration. The role installs dnsmasq, replaces /etc/dnsmasq.conf (root 0644, checked by dnsmasq --test first; it still includes /etc/dnsmasq.d/*.conf) and enables the package's dnsmasq.service, which drops to the dnsmasq user. The listener is 127.0.0.1:53 by default; the live test reads the TCP and UDP sockets and expects loopback only.

listen-address alone still listens everywhere. Give dnsmasq a listen-address without bind-interfaces and it opens 0.0.0.0:53 and [::]:53 and filters in software: a client on another interface timed out rather than being refused, and nothing else can bind port 53 (measured). The role always writes bind-interfaces, so the listed addresses are the only sockets.

What the package sends upstream. By default dnsmasq forwards a plain name (nas) and a reverse lookup for a private address (10.9.8.7) to the public resolver, and passes on an upstream answer that points a public name at a private address - the move a DNS rebinding attack needs. The role sets domain-needed, bogus-priv and stop-dns-rebind: the live test reads dnsmasq's own per-server counters (servers.bind) and finds them unchanged after a plain name, a private reverse lookup and a miss in the local domain, then changed after a public name; and a test upstream's private answer is dropped, with "possible DNS-rebind attack detected" in the journal. Answers in 127.0.0.0/8 stay allowed (dnsmasq_rebind_localhost_ok), because DNS blocklists use them. dnsmasq also treats the documentation ranges as private.

DNSSEC validated by the cache itself. With dnsmasq_dnssec dnsmasq checks signatures and flags a good answer ad; with it off, the flag is gone (the live test reads it). A broken signature (dnssec-failed.org) answers SERVFAIL - but Quad9, the default upstream, returns that by itself too, so with Quad9 that part is not dnsmasq's doing; it is with an upstream that does not validate.

Every name checked after a start. dnsmasq --test passes a host-record whose address does not parse, and that name then answers NXDOMAIN (measured). The role asks for each name in dnsmasq_hosts after every start and fails on any that does not answer the addresses it wrote.

License

Commercial - IaC Bazaar EULA. (c) IaC Bazaar.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Variables
  • Test

Related modules

Live-tested

ansible-unbound-resolver

Unbound on loopback: DNSSEC validated locally against the root anchor, query names minimised, version hidden, and upstream over DNS-over-TLS by default because many networks reset TCP 53 to anything but a known resolver, which breaks full recursion the moment a DNSKEY answer outgrows UDP. Recursion is one setting away. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-bind-authoritative

BIND as an authoritative-only server. The package is a loopback resolver; add a zone and anyone who can query can copy the whole zone, and version.bind names the 9.18 to attack. This role turns recursion off, refuses transfers to anyone not listed, hides the identity records, rate-limits responses, and renders zones from data checked before they land. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-coredns

CoreDNS from the upstream release (sha256-verified) as a hardened system service answering authoritatively for your zones on 127.0.0.1:53 as a system user (CAP_NET_BIND_SERVICE through the unit), forwarding only when you name upstreams. The live test digs the example zone's A record with the aa flag, an NXDOMAIN in the zone and a REFUSED outside it. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-nsd

NSD from EPEL: an authoritative-only server for your zones, the configuration and every zone checked by NSD's own tools first, transfers only to the addresses and TSIG keys you name, response rate limiting, and the state directory the package leaves unwritable fixed. The live test gets the zone with the key and is refused without it. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-pdns-recursor

PowerDNS Recursor from EPEL on loopback: DNSSEC validated, and every upstream query sent over DNS-over-TLS with each forwarder's certificate checked against the name it must carry. The live test counts every upstream query as TLS, gets SERVFAIL for a broken signature, and has a copy naming the wrong certificate answer nothing. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-powerdns

PowerDNS authoritative from EPEL with its SQLite backend; the live test adds a zone through the API, gets the record from dig and NXDOMAIN for an unknown name, sees the API refuse a caller with no key, and reads the query counter. The schema is recovered when a docs-stripped host lacks it. Original role, live-tested on Rocky Linux 10.

View module