惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Tenable Blog
C
Cybersecurity and Infrastructure Security Agency CISA
P
Palo Alto Networks Blog
N
News | PayPal Newsroom
L
Lohrmann on Cybersecurity
S
Schneier on Security
C
CXSECURITY Database RSS Feed - CXSecurity.com
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
IT之家
IT之家
云风的 BLOG
云风的 BLOG
博客园_首页
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
C
Cyber Attacks, Cyber Crime and Cyber Security
量子位
人人都是产品经理
人人都是产品经理
S
Securelist
Last Week in AI
Last Week in AI
V
V2EX
Simon Willison's Weblog
Simon Willison's Weblog
AWS News Blog
AWS News Blog
I
Intezer
T
The Exploit Database - CXSecurity.com
雷峰网
雷峰网
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
美团技术团队
Project Zero
Project Zero
博客园 - 叶小钗
Cyberwarzone
Cyberwarzone
A
Arctic Wolf
月光博客
月光博客
大猫的无限游戏
大猫的无限游戏
阮一峰的网络日志
阮一峰的网络日志
博客园 - 【当耐特】
M
MIT News - Artificial intelligence
P
Privacy International News Feed
Blog — PlanetScale
Blog — PlanetScale
C
Cisco Blogs
G
GRAHAM CLULEY
V
Vulnerabilities – Threatpost
K
Kaspersky official blog
P
Proofpoint News Feed
NISL@THU
NISL@THU
Latest news
Latest news
Scott Helme
Scott Helme
The Hacker News
The Hacker News
Know Your Adversary
Know Your Adversary
F
Full Disclosure
The Cloudflare Blog
Spread Privacy
Spread Privacy
H
Hacker News: Front Page

Plugin on CoreDNS: DNS and Service Discovery

kubernetes log proxyproto rewrite forward clouddns errors grpc_server https https3 docker auto geoip multisocket nomad dnstap import ready etcd header loadbalance bind grpc file prometheus quic kubeforward JSON gslb autopath dnssec root fanout k8s_cache bufsize k8s_external reload gathersrv meship meshname multicluster acl cache recursor health trace k8s_event redis route53 dns64 finalize kubenodes ebpf rrl secondary mysql warnlist loop minimal sign azure git local any cancel debug erratic metadata nsid pprof k8s_dns_chaos records k8s_gateway hosts netbox mdns wgsd alias chaos whoami lighthouse ens idetcd gravwell amazondns kubernetai redisc unbound on dump pdsql ipin Logging with dnstap demo example When Should Plugins be External? Add External Plugins How Queries Are Processed in CoreDNS How to Add Plugins to CoreDNS Writing Plugins for CoreDNS
alternate
2020-09-28 · via Plugin on CoreDNS: DNS and Service Discovery

Description

The alternate plugin is able to selectively forward queries to another upstream server, depending the error result provided by the initial resolver. It allows an alternate set of upstreams be specified which will be used if the plugin chain returns specific error messages. The alternate plugin utilizes the forward plugin (https://coredns.io/plugins/forward) to query the specified upstreams.

The alternate plugin supports only DNS protocol and random policy w/o additional forward parameters, so following directives will fail:

. {
    forward . 8.8.8.8
    alternate NXDOMAIN . tls://192.168.1.1:853 {
        policy sequential
    }
}

As the name suggests, the purpose of the alternate is to allow a alternate when, for example, the desired upstreams became unavailable.

Syntax

{
    alternate [original] RCODE_1[,RCODE_2,RCODE_3...] . DNS_RESOLVERS
}
  • original is optional flag. If it is set then alternate uses original request instead of potentially changed by other plugins
  • RCODE is the string representation of the error response code. The complete list of valid rcode strings are defined as RcodeToString in https://github.com/miekg/dns/blob/master/msg.go, examples of which are SERVFAIL, NXDOMAIN and REFUSED. At least one rcode is required, but multiple rcodes may be specified, delimited by commas.
  • DNS_RESOLVERS accepts dns resolvers list.

Examples

Alternate to local DNS server

The following specifies that all requests are forwarded to 8.8.8.8. If the response is NXDOMAIN, alternate will forward the request to 192.168.1.1:53, and reply to client accordingly.

. {
	forward . 8.8.8.8
	alternate NXDOMAIN . 192.168.1.1:53
	log
}

Alternate with original request used

The following specify that original query will be forwarded to 192.168.1.1:53 if 8.8.8.8 response is NXDOMAIN. original means no changes from next plugins on request. With no original flag alternate will forward request with EDNS0 option (set by rewrite).

. {
	forward . 8.8.8.8
	rewrite edns0 local set 0xffee 0x61626364
	alternate original NXDOMAIN . 192.168.1.1:53
	log
}

Multiple alternates

Multiple alternates can be specified, as long as they serve unique error responses.

. {
    forward . 8.8.8.8
    alternate NXDOMAIN . 192.168.1.1:53
    alternate original SERVFAIL,REFUSED . 192.168.100.1:53
    log
}