惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
H
Help Net Security
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
V
Vulnerabilities – Threatpost
MongoDB | Blog
MongoDB | Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
A
Arctic Wolf
The GitHub Blog
The GitHub Blog
Security Latest
Security Latest
G
GRAHAM CLULEY
Cyberwarzone
Cyberwarzone
S
Schneier on Security
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
P
Privacy & Cybersecurity Law Blog
IT之家
IT之家
D
Darknet – Hacking Tools, Hacker News & Cyber Security
博客园 - 聂微东
T
Threat Research - Cisco Blogs
AWS News Blog
AWS News Blog
The Hacker News
The Hacker News
B
Blog RSS Feed
云风的 BLOG
云风的 BLOG
Scott Helme
Scott Helme
P
Proofpoint News Feed
T
The Exploit Database - CXSecurity.com
L
LangChain Blog
F
Full Disclosure
I
Intezer
V
V2EX
C
Cyber Attacks, Cyber Crime and Cyber Security
Cisco Talos Blog
Cisco Talos Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Spread Privacy
Spread Privacy
美团技术团队
Engineering at Meta
Engineering at Meta
C
Cybersecurity and Infrastructure Security Agency CISA
罗磊的独立博客
T
Tenable Blog
D
DataBreaches.Net
M
MIT News - Artificial intelligence
S
Securelist
C
CERT Recently Published Vulnerability Notes
Recent Announcements
Recent Announcements
Microsoft Azure Blog
Microsoft Azure Blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
NISL@THU
NISL@THU
The Register - Security
The Register - Security
L
LINUX DO - 热门话题
P
Palo Alto Networks Blog

multisocket on CoreDNS: DNS and Service Discovery

暂无文章

multisocket
2025-12-11 · via multisocket on CoreDNS: DNS and Service Discovery

Description

With multisocket, you can define the number of servers that will listen on the same port. The SO_REUSEPORT socket option allows to open multiple listening sockets at the same address and port. In this case, kernel distributes incoming connections between sockets.

Enabling this option allows to start multiple servers, which increases the throughput of CoreDNS in environments with a large number of CPU cores.

Syntax

multisocket [NUM_SOCKETS]
  • NUM_SOCKETS - the number of servers that will listen on one port. Default value is equal to GOMAXPROCS. Maximum value is 1024.

Examples

Start 5 TCP/UDP servers on the same port.

. {
	multisocket 5
	forward . /etc/resolv.conf
}

Do not define NUM_SOCKETS, in this case it will take a value equal to GOMAXPROCS.

. {
	multisocket
	forward . /etc/resolv.conf
}

Recommendations

The tests of the multisocket plugin, which were conducted for NUM_SOCKETS from 1 to 10, did not reveal any side effects or performance degradation.

This means that the multisocket plugin can be used with a default value that is equal to GOMAXPROCS.

However, to achieve the best results, it is recommended to consider the specific environment and plugins used in CoreDNS. To determine the optimal configuration, it is advisable to conduct performance tests with different NUM_SOCKETS, measuring Queries Per Second (QPS) and system load.

If conducting such tests is difficult, follow these recommendations:

  1. Determine the maximum CPU consumption of CoreDNS server without multisocket plugin. Estimate how much CPU CoreDNS actually consumes in specific environment under maximum load.
  2. Align NUM_SOCKETS with the estimated CPU usage and CPU limits or system’s available resources. Examples:
    • If CoreDNS consumes 4 CPUs and 8 CPUs are available, set NUM_SOCKETS to 2.
    • If CoreDNS consumes 8 CPUs and 64 CPUs are available, set NUM_SOCKETS to 8.

Limitations

The multisocket value used for a given listen address is taken from the first server block that binds to that address in the Corefile. Subsequent server blocks using the same address will not change it. Different addresses may use different values.

The SO_REUSEPORT socket option is not available for some operating systems. It is available since Linux Kernel 3.9 and not available for Windows at all.

Using this plugin with a system that does not support SO_REUSEPORT will cause an address already in use error.