PowerDNS, A Zone It Answers For, From SQLite
PowerDNS authoritative from EPEL with its SQLite backend; the live test adds a zone through the API, gets the record from dig and NXDOMAIN for an unknown name, sees the API refuse a caller with no key, and reads the query counter. The schema is recovered when a docs-stripped host lacks it. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-09-26 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-powerdns?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [PowerDNS, A Zone It Answers For, From SQLite](https://www.iac-bazaar.com/catalog/ansible-powerdns?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# PowerDNS, A Zone It Answers For, From SQLite: https://www.iac-bazaar.com/catalog/ansible-powerdns (download from your IaC Bazaar account)
```Preview:
Documentation
powerdns
PowerDNS, the authoritative server, from EPEL with its SQLite backend, its zone database created from the schema the package ships, and its HTTP API on loopback behind a key. Original role for EL 10, live-tested with podman on Rocky Linux 10.
No download, and no version to pin. EL 10 packages pdns in EPEL, so the
role installs it by name and takes what the distribution ships: a security
update arrives through dnf, not through a new release of this role. What the
role owns is the configuration and the proof that the service works.
The distribution's unit, our configuration. The role installs
pdns, pdns-backend-sqlite, sqlite, writes the configuration the package leaves open, and enables
the unit the package ships: systemctl cat pdns shows the
distribution's own unit, not one this role invented. The listener is
127.0.0.1 by default, for a proxy that authenticates or a client
on the same host; the live test reads the listening sockets and expects
loopback only.
Proven by a zone it answers for. The live test adds a zone through the API, asks the server for a record in it with dig and gets the address, asks for a name that does not exist and gets NXDOMAIN, sees the API refuse a caller with no key, and reads the backend query counter from /metrics.
The schema is documentation, which a hardened host may not have. The
sqlite3 backend needs its tables created once from
/usr/share/doc/pdns/schema.sqlite3.sql, and an image built with
tsflags=nodocs (every container base, and some minimal installs) has the
package without that file. The role looks for it and reinstalls the backend
package with its documentation when it is missing, rather than shipping a
copy of a schema whose version has to match the package's.
Port 5300 by default, 53 when you mean it. The package's own unit
carries CAP_NET_BIND_SERVICE, so setting powerdns_port: 53 needs no
other change; the default keeps the role testable beside a host resolver.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-unbound-resolver
Unbound on loopback: DNSSEC validated locally against the root anchor, query names minimised, version hidden, and upstream over DNS-over-TLS by default because many networks reset TCP 53 to anything but a known resolver, which breaks full recursion the moment a DNSKEY answer outgrows UDP. Recursion is one setting away. Original role, live-tested on Rocky Linux 10.
ansible-bind-authoritative
BIND as an authoritative-only server. The package is a loopback resolver; add a zone and anyone who can query can copy the whole zone, and version.bind names the 9.18 to attack. This role turns recursion off, refuses transfers to anyone not listed, hides the identity records, rate-limits responses, and renders zones from data checked before they land. Original role, live-tested on Rocky Linux 10.
ansible-coredns
CoreDNS from the upstream release (sha256-verified) as a hardened system service answering authoritatively for your zones on 127.0.0.1:53 as a system user (CAP_NET_BIND_SERVICE through the unit), forwarding only when you name upstreams. The live test digs the example zone's A record with the aa flag, an NXDOMAIN in the zone and a REFUSED outside it. Original role, live-tested on Rocky Linux 10.
ansible-bind-exporter
bind_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test brings up named with one zone and a statistics channel on loopback as a fixture, asks it a name with dig, and reads bind_up 1 and the A query counted. Original role, live-tested on Rocky Linux 10.