secdns — internal authoritative DNS¶
secdns is a small, zero-dependency (standard library only) authoritative DNS server that
serves an internal zone so the suite’s components resolve each other by name across hosts —
so a multi-host deployment gets real name resolution instead of scattered /etc/hosts edits.
What it does¶
Authoritative for one internal zone (default
sec.internal), answeringA/AAAA/TXTfrom a simple zone file, with correctNXDOMAIN/NODATAresolver behavior.Forwards non-internal queries to upstream resolvers, or refuses them when no upstream is configured — the closed-network default, so nothing leaks out.
UDP + TCP on port 53, with live reload (
kill -HUPor the console’s Reload button) and no downtime.Status console — a tiny HTTP page with the served records, live query stats, and
/healthfor probes.In the suite, SecDeploy generates the zone file from your
topology.toml— one record per component, pointing at wherever it’s actually hosted.Tamper-evident audit — lifecycle events (start/stop, zone load/reload — never per-query) are recorded to a hash-chained JSONL log.
Quickstart¶
uv sync
cp zones/secdns.zone.example zones/secdns.zone
uv run secdns serve --domain sec.internal --zone zones/secdns.zone \
--upstream 1.1.1.1 --port 5353
dig @127.0.0.1 -p 5353 secrouter.sec.internal
Learn more¶
secdns on GitHub — source, issues, releases.
secdns docs — the config reference, zone file format, console, deployment, and control validation.