Many changes! Shipping STABLE @nlnetlabs Unbound QUIC builds aside our non QUIC variant&our cutting-edge canary builds soon! The supported architectures have been ramped up too: ppc64le, s390x, riscv64 joined the party. No own unbound.conf anymore, now we're just patching the needed #recursor settings at buildtime.

Test driving our builds verifies everything is nice. 💚

https://github.com/madnuttah/unbound-docker

#DNS #DNSSEC #DoT #DoH #QUIC #HTTP3 #Unbound #FOSS #SelfHosting #Homelab #Privacy #Security #ci #cd

GitHub - madnuttah/unbound-docker: 🛡️ This distroless Unbound Docker image is based on Alpine Linux with focus on security, privacy, performance and a small image size. And with Pi-hole in mind.

🛡️ This distroless Unbound Docker image is based on Alpine Linux with focus on security, privacy, performance and a small image size. And with Pi-hole in mind. - madnuttah/unbound-docker

GitHub

"PowerDNS Security Advisory 2025-01: A crafted zone can lead to an illegal memory access in the Recursor"

https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2025-01.html #powerdns #security #recursor

PowerDNS Security Advisory 2025-01: A crafted zone can lead to an illegal memory access in the Recursor — PowerDNS Recursor documentation

@pemensik The reason why you uninstall it as the first thing on a fresh install, then you install either Powerdns's #recursor (+ #dnsdist ) or #Unbound and then you are #RFC compliant

@Alonely0 @floppy_bv You just need a Linux installation with either Powerdns's #recursor (+dnsdist) or #unbound with #RPZ.

All less than 100mb ram if you uses @mypdns #RPZ #DNS #Firewall zones, you didn't need an entire hardware device, a virtual install is sufficient for most home users, the cool with RPZ over any (dumb) hosts driven system is, is the structure in it and that it do understand how to drop on IP addresses

RPZ · Wiki · My Privacy DNS / Matrix · GitLab

Handcrafted and completely self managed DNS Firewall through Response Policy Zones (RPZ)

GitLab