Autosecondary SOA and NS checks aren't recursive and can't go through powerdns recursor #15013
Replies: 4 comments 5 replies
-
Is there a reason why you would ever want dnsdist to direct these You may want to consider filtering based on |
Beta Was this translation helpful? Give feedback.
-
My point is that recursor is already aware of where to route my domain and others. So adding more rules to dnsdist I'm repeating the same rules that recursor already has. |
Beta Was this translation helpful? Give feedback.
-
I was imagining something simple like this to have all the non-recursor stuff going to the right place:
Idk about this |
Beta Was this translation helpful? Give feedback.
-
Good point, I was thinking that way but haven't reached a decision yet :) |
Beta Was this translation helpful? Give feedback.
-
Short description
When secondary gets a new domain it makes SOA and NS queries to primary. As my auth primary is below dnsdist it is convenient to pass most of queries to recursor which sends queries for my domain to auth pdns server.
But pdns_server does these queries w/o recursion, so they don't pass.
I solve that using dnsdist rules to route NS and SOA requests to my domain directly to auth server, but still I can't see why these queries aren't recursive.
Environment
noble/universe
Ubuntu repositorySteps to reproduce
we are not authoritative, trying supermaster
and further.Expected behaviour
I expect SOA and NS check pass through recursor to auth.
Actual behaviour
SOA and NS check die at recursor as
rd=0
.Other information
Beta Was this translation helpful? Give feedback.
All reactions