NSD Authoritative DNS With Keyed Zone Transfers
NSD from EPEL: an authoritative-only server for your zones, the configuration and every zone checked by NSD's own tools first, transfers only to the addresses and TSIG keys you name, response rate limiting, and the state directory the package leaves unwritable fixed. The live test gets the zone with the key and is refused without it. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-10-03 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-nsd?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [NSD Authoritative DNS With Keyed Zone Transfers](https://www.iac-bazaar.com/catalog/ansible-nsd?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# NSD Authoritative DNS With Keyed Zone Transfers: https://www.iac-bazaar.com/catalog/ansible-nsd (download from your IaC Bazaar account)
```Preview:
Documentation
nsd
NSD from EPEL: an authoritative-only DNS server for the zones you list, with transfers allowed only to the addresses and TSIG keys you name, response rate limiting, the version and identity hidden, and nsd-control on a local socket. Original role for EL 10, live-tested with podman on Rocky Linux 10.
No download, and no version to pin. EL 10 packages nsd in EPEL, so the
role installs it by name and takes what the distribution ships: a security
update arrives through dnf, not through a new release of this role. What the
role owns is the configuration and the proof that the service works.
The package cannot keep its transfer state. EPEL's nsd leaves
/var/lib/nsd as root:root 0750, while nsd's transfer daemon runs as the nsd
user, so it can neither read nor write ixfr.state there: "Permission denied"
at every start and every stop (measured). The role gives the directory to nsd,
and the live test restarts the service and finds the state file written, owned
by nsd, with no "Permission denied" in the log. The listener is 127.0.0.1:53
by default, for a resolver or dnsdist on the same host; list your public
addresses in nsd_listen_address and nsd_extra_ip_addresses to serve the
world.
Control without keys. A TCP control port needs TLS keys from
nsd-control-setup, which calls openssl - not installed in a minimal image -
and nsd then refuses to start ("could not setup remote control TLS context",
measured). The role uses the stock UNIX socket, /run/nsd/nsd.ctl, which only
root and the nsd group can open, and needs no keys.
Proven by transfers. The configuration is checked by nsd-checkconf (exit 2
on a typo, a bad algorithm or an undefined key) and every zone by
nsd-checkzone before it lands. The live test gets an authoritative answer
(aa), a REFUSED for a zone nsd does not serve and for version.bind, the zone
by AXFR when signed with the role's generated key - and a refusal without the
key, with a wrong key, and with the right key from an address the zone does not
list. A burst of 100 queries from one address is cut to at most 60 full answers
with some truncated, and the server answers in full again within ten seconds.
The rate decays over seconds: two seconds after a burst a query was sometimes
still truncated (measured), so the test asks once a second rather than once.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-unbound-resolver
Unbound on loopback: DNSSEC validated locally against the root anchor, query names minimised, version hidden, and upstream over DNS-over-TLS by default because many networks reset TCP 53 to anything but a known resolver, which breaks full recursion the moment a DNSKEY answer outgrows UDP. Recursion is one setting away. Original role, live-tested on Rocky Linux 10.
ansible-bind-authoritative
BIND as an authoritative-only server. The package is a loopback resolver; add a zone and anyone who can query can copy the whole zone, and version.bind names the 9.18 to attack. This role turns recursion off, refuses transfers to anyone not listed, hides the identity records, rate-limits responses, and renders zones from data checked before they land. Original role, live-tested on Rocky Linux 10.
ansible-coredns
CoreDNS from the upstream release (sha256-verified) as a hardened system service answering authoritatively for your zones on 127.0.0.1:53 as a system user (CAP_NET_BIND_SERVICE through the unit), forwarding only when you name upstreams. The live test digs the example zone's A record with the aa flag, an NXDOMAIN in the zone and a REFUSED outside it. Original role, live-tested on Rocky Linux 10.
ansible-powerdns
PowerDNS authoritative from EPEL with its SQLite backend; the live test adds a zone through the API, gets the record from dig and NXDOMAIN for an unknown name, sees the API refuse a caller with no key, and reads the query counter. The schema is recovered when a docs-stripped host lacks it. Original role, live-tested on Rocky Linux 10.
ansible-bind-exporter
bind_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test brings up named with one zone and a statistics channel on loopback as a fixture, asks it a name with dig, and reads bind_up 1 and the A query counted. Original role, live-tested on Rocky Linux 10.
ansible-dnsdist
dnsdist from EPEL, whose own unit cannot read the config the package installs; the role fixes the ownership, adds an ACL, a per-client query limit and a packet cache, stops the security poll, and keys the console. The live test sees a client outside the ACL dropped, a 100-query burst cut to 20, and a wrong console key refused. Original role, live-tested on Rocky Linux 10.