DNS

activesnapshotverified 2026-07-20

Status: active Last verified: 2026-07-20 (against the current DNS service and resolver host records) Scope: public resolver architecture and policy; changing counts remain approximate

Purpose

Network-wide recursive DNS with DNSSEC validation, authoritative zones for home.arpa, and ad-blocking.

Current Shape

ServerRoleHostOSContainer
ns1Primary resolver + authoritativeProxmox host ADebian 12LXC
ns2Secondary resolver + authoritativeProxmox host BDebian 12LXC
FeatureDetail
ResolverUnbound (pure recursive)
DNSSECValidation enabled
Authoritativehome.arpa zone
Ad-blockingOISD Big + StevenBlack (~395K domains)
DoH blockingDNS-over-HTTPS bypass attempts blocked
Access controlRFC 1918 + localhost only
Cache priming3x/day + hourly dynamic list (ns2)
ConfigAnsible-managed

Migration

Both servers migrated from VMs to unprivileged LXC containers in April 2026 for reduced overhead and faster startup (1-2 seconds vs 15-30 seconds). Old VMs decommissioned after confirmation.

Backup

Protected by Proxmox Backup Server with daily snapshots and a same-rack secondary copy.

Constraints

Drift / Unknowns