| 
									
										
										
										
											2017-08-12 23:34:56 -07:00
										 |  |  | [](https://coredns.io) | 
					
						
							| 
									
										
										
										
											2016-03-18 21:31:55 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-08-09 09:58:32 -07:00
										 |  |  | [](https://godoc.org/github.com/coredns/coredns) | 
					
						
							|  |  |  | [](https://travis-ci.org/coredns/coredns) | 
					
						
							|  |  |  | [](https://codecov.io/github/coredns/coredns?branch=master) | 
					
						
							|  |  |  | [](https://goreportcard.com/report/coredns/coredns) | 
					
						
							| 
									
										
										
										
											2017-05-08 09:31:26 -05:00
										 |  |  | [](https://app.fossa.io/projects/git%2Bhttps%3A%2F%2Fgithub.com%2Fcoredns%2Fcoredns?ref=badge_shield) | 
					
						
							| 
									
										
										
										
											2017-09-12 09:38:14 -04:00
										 |  |  | [](https://bestpractices.coreinfrastructure.org/projects/1250) | 
					
						
							| 
									
										
										
										
											2016-09-25 08:39:20 +01:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-03-13 20:24:37 +00:00
										 |  |  | CoreDNS is a DNS server that started as a fork of [Caddy](https://github.com/mholt/caddy/). It has | 
					
						
							| 
									
										
										
										
											2017-09-15 23:49:20 +01:00
										 |  |  | the same model: it chains plugins. | 
					
						
							| 
									
										
										
										
											2017-03-19 09:12:18 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-09-15 23:49:20 +01:00
										 |  |  | CoreDNS is a [Cloud Native Computing Foundation](https://cncf.io) inception level project. | 
					
						
							| 
									
										
										
										
											2016-03-18 21:31:55 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-08-22 13:48:23 -07:00
										 |  |  | CoreDNS is the successor to [SkyDNS](https://github.com/skynetservices/skydns). SkyDNS is a thin | 
					
						
							| 
									
										
										
										
											2017-10-10 09:39:35 +02:00
										 |  |  | layer that exposes services in etcd in the DNS. CoreDNS builds on this idea and is a **generic** DNS | 
					
						
							| 
									
										
										
										
											2016-09-17 21:28:59 +01:00
										 |  |  | server that can talk to multiple backends (etcd, kubernetes, etc.). | 
					
						
							| 
									
										
										
										
											2016-06-26 15:28:27 +01:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-08-22 13:48:23 -07:00
										 |  |  | CoreDNS aims to be a fast and flexible DNS server. The keyword here is *flexible*: with CoreDNS you | 
					
						
							| 
									
										
										
										
											2017-09-15 23:49:20 +01:00
										 |  |  | are able to do what you want with your DNS data. And if not: write a plugin! | 
					
						
							| 
									
										
										
										
											2016-04-24 08:11:00 +01:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-03-19 09:12:18 +00:00
										 |  |  | CoreDNS can listen for DNS request coming in over UDP/TCP (go'old DNS), TLS ([RFC | 
					
						
							| 
									
										
										
										
											2017-03-29 08:24:08 +00:00
										 |  |  | 7858](https://tools.ietf.org/html/rfc7858)) and gRPC (not a standard). | 
					
						
							| 
									
										
										
										
											2017-03-13 20:24:37 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-04-03 19:05:49 +01:00
										 |  |  | Currently CoreDNS is able to: | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-10-18 07:47:18 +01:00
										 |  |  | * Serve zone data from a file; both DNSSEC (NSEC only) and DNS are supported (*file*). | 
					
						
							|  |  |  | * Retrieve zone data from primaries, i.e., act as a secondary server (AXFR only) (*secondary*). | 
					
						
							|  |  |  | * Sign zone data on-the-fly (*dnssec*). | 
					
						
							|  |  |  | * Load balancing of responses (*loadbalance*). | 
					
						
							|  |  |  | * Allow for zone transfers, i.e., act as a primary server (*file*). | 
					
						
							| 
									
										
										
										
											2017-03-29 08:24:08 +00:00
										 |  |  | * Automatically load zone files from disk (*auto*). | 
					
						
							| 
									
										
										
										
											2016-10-18 07:47:18 +01:00
										 |  |  | * Caching (*cache*). | 
					
						
							|  |  |  | * Health checking endpoint (*health*). | 
					
						
							| 
									
										
										
										
											2016-08-22 13:48:23 -07:00
										 |  |  | * Use etcd as a backend, i.e., a 101.5% replacement for | 
					
						
							| 
									
										
										
										
											2016-10-18 07:47:18 +01:00
										 |  |  |   [SkyDNS](https://github.com/skynetservices/skydns) (*etcd*). | 
					
						
							|  |  |  | * Use k8s (kubernetes) as a backend (*kubernetes*). | 
					
						
							|  |  |  | * Serve as a proxy to forward queries to some other (recursive) nameserver (*proxy*). | 
					
						
							|  |  |  | * Provide metrics (by using Prometheus) (*metrics*). | 
					
						
							|  |  |  | * Provide query (*log*) and error (*error*) logging. | 
					
						
							|  |  |  | * Support the CH class: `version.bind` and friends (*chaos*). | 
					
						
							|  |  |  | * Profiling support (*pprof*). | 
					
						
							|  |  |  | * Rewrite queries (qtype, qclass and qname) (*rewrite*). | 
					
						
							|  |  |  | * Echo back the IP address, transport and port number used (*whoami*). | 
					
						
							| 
									
										
										
										
											2016-04-20 12:46:24 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-10-10 09:39:35 +02:00
										 |  |  | Each of the plugins has a README.md of its own, see [coredns.io/plugins](https://coredns.io/plugins) | 
					
						
							|  |  |  | for all in-tree plugins. | 
					
						
							| 
									
										
										
										
											2016-08-22 07:47:03 +01:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-04-20 12:46:24 +00:00
										 |  |  | ## Status
 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-09-15 23:49:20 +01:00
										 |  |  | CoreDNS can be used as an authoritative nameserver for your domains. All in all, CoreDNS should be | 
					
						
							|  |  |  | able to provide you with enough functionality to replace parts of BIND 9, Knot, NSD or PowerDNS and | 
					
						
							|  |  |  | SkyDNS. Most documentation is in the source and blog articles can be [found | 
					
						
							|  |  |  | here](https://coredns.io). If you do want to use CoreDNS in production, please let us know. | 
					
						
							| 
									
										
										
										
											2016-03-18 21:36:42 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-08-19 17:14:17 -07:00
										 |  |  | ## Compilation
 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-10-10 09:39:35 +02:00
										 |  |  | If you have the source of CoreDNS checked out in the appropriate place in your `GOPATH`, get all | 
					
						
							|  |  |  | dependencies: | 
					
						
							| 
									
										
										
										
											2016-08-19 17:14:17 -07:00
										 |  |  | 
 | 
					
						
							|  |  |  |     go get ./... | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-09-13 22:03:56 +01:00
										 |  |  | (You can do the checkout and dependency resolution as a single step with: `go get github.com/coredns/coredns`.) | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-09-17 21:28:59 +01:00
										 |  |  | And then `go build` as you would normally do: | 
					
						
							| 
									
										
										
										
											2016-08-19 17:14:17 -07:00
										 |  |  | 
 | 
					
						
							|  |  |  |     go build | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-08-22 13:48:23 -07:00
										 |  |  | This should yield a `coredns` binary. | 
					
						
							| 
									
										
										
										
											2016-08-19 17:14:17 -07:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-09-15 23:49:20 +01:00
										 |  |  | ## Compilation with Docker
 | 
					
						
							| 
									
										
										
										
											2017-09-13 16:36:20 -07:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-09-15 23:49:20 +01:00
										 |  |  | CoreDNS requires Go to compile. However, if you already have docker installed and prefer not to setup | 
					
						
							|  |  |  | a Go environment, you could build coredns easily: | 
					
						
							| 
									
										
										
										
											2017-09-13 16:36:20 -07:00
										 |  |  | 
 | 
					
						
							|  |  |  | ``` | 
					
						
							|  |  |  | $ docker run --rm -i -t -v $PWD:/go/src/github.com/coredns/coredns \ | 
					
						
							|  |  |  |       -w /go/src/github.com/coredns/coredns golang:1.9 make | 
					
						
							|  |  |  | ``` | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | The above command alone will have `coredns` binary generated. | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-04-03 20:30:37 +01:00
										 |  |  | ## Examples
 | 
					
						
							| 
									
										
										
										
											2016-03-18 21:36:42 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-10-10 09:39:35 +02:00
										 |  |  | When starting CoreDNS without any configuration, it loads the | 
					
						
							|  |  |  | [*whoami*](https://coredns.io/plugins/whoami) plugin and starts | 
					
						
							| 
									
										
										
										
											2016-10-18 07:47:18 +01:00
										 |  |  | listening on port 53 (override with `-dns.port`), it should show the following: | 
					
						
							| 
									
										
										
										
											2016-09-18 09:32:06 +01:00
										 |  |  | 
 | 
					
						
							|  |  |  | ~~~ txt | 
					
						
							| 
									
										
										
										
											2016-10-18 07:47:18 +01:00
										 |  |  | .:53 | 
					
						
							| 
									
										
										
										
											2016-10-07 10:14:23 +00:00
										 |  |  | 2016/09/18 09:20:50 [INFO] CoreDNS-001 | 
					
						
							|  |  |  | CoreDNS-001 | 
					
						
							| 
									
										
										
										
											2016-09-18 09:32:06 +01:00
										 |  |  | ~~~ | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-10-18 07:47:18 +01:00
										 |  |  | Any query send to port 53 should return some information; your sending address, port and protocol | 
					
						
							| 
									
										
										
										
											2016-09-18 09:32:06 +01:00
										 |  |  | used. | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-10-18 07:47:18 +01:00
										 |  |  | If you have a Corefile without a port number specified it will, by default, use port 53, but you | 
					
						
							|  |  |  | can override the port with the `-dns.port` flag: | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | `./coredns -dns.port 1053`, runs the server on port 1053. | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-08-22 07:47:03 +01:00
										 |  |  | Start a simple proxy, you'll need to be root to start listening on port 53. | 
					
						
							| 
									
										
										
										
											2016-03-18 21:36:42 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  | `Corefile` contains: | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-04-03 20:30:37 +01:00
										 |  |  | ~~~ txt | 
					
						
							| 
									
										
										
										
											2016-08-22 07:47:03 +01:00
										 |  |  | .:53 { | 
					
						
							| 
									
										
										
										
											2016-03-18 21:36:42 +00:00
										 |  |  |     proxy . 8.8.8.8:53 | 
					
						
							| 
									
										
										
										
											2017-09-15 23:49:20 +01:00
										 |  |  |     log | 
					
						
							| 
									
										
										
										
											2016-03-18 21:36:42 +00:00
										 |  |  | } | 
					
						
							|  |  |  | ~~~ | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-09-15 23:49:20 +01:00
										 |  |  | Just start CoreDNS: `./coredns`. Then just query on that port (53). The query should be forwarded to | 
					
						
							|  |  |  | 8.8.8.8 and the response will be returned. Each query should also show up in the log. | 
					
						
							| 
									
										
										
										
											2016-03-20 08:45:21 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-09-18 09:32:06 +01:00
										 |  |  | Serve the (NSEC) DNSSEC-signed `example.org` on port 1053, with errors and logging sent to stdout. | 
					
						
							| 
									
										
										
										
											2017-05-30 16:03:35 +02:00
										 |  |  | Allow zone transfers to everybody, but specifically mention 1 IP address so that CoreDNS can send | 
					
						
							| 
									
										
										
										
											2016-09-18 09:32:06 +01:00
										 |  |  | notifies to it. | 
					
						
							| 
									
										
										
										
											2016-04-03 20:30:37 +01:00
										 |  |  | 
 | 
					
						
							|  |  |  | ~~~ txt | 
					
						
							| 
									
										
										
										
											2016-08-22 07:47:03 +01:00
										 |  |  | example.org:1053 { | 
					
						
							|  |  |  |     file /var/lib/coredns/example.org.signed { | 
					
						
							| 
									
										
										
										
											2016-04-03 20:30:37 +01:00
										 |  |  |         transfer to * | 
					
						
							| 
									
										
										
										
											2016-08-22 07:47:03 +01:00
										 |  |  |         transfer to 2001:500:8f::53 | 
					
						
							| 
									
										
										
										
											2016-04-03 20:30:37 +01:00
										 |  |  |     } | 
					
						
							| 
									
										
										
										
											2017-09-15 23:49:20 +01:00
										 |  |  |     errors | 
					
						
							|  |  |  |     log | 
					
						
							| 
									
										
										
										
											2016-04-03 20:30:37 +01:00
										 |  |  | } | 
					
						
							|  |  |  | ~~~ | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-08-22 07:47:03 +01:00
										 |  |  | Serve `example.org` on port 1053, but forward everything that does *not* match `example.org` to a recursive | 
					
						
							| 
									
										
										
										
											2016-04-03 20:30:37 +01:00
										 |  |  | nameserver *and* rewrite ANY queries to HINFO. | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | ~~~ txt | 
					
						
							|  |  |  | .:1053 { | 
					
						
							|  |  |  |     rewrite ANY HINFO | 
					
						
							|  |  |  |     proxy . 8.8.8.8:53 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-08-22 07:47:03 +01:00
										 |  |  |     file /var/lib/coredns/example.org.signed example.org { | 
					
						
							| 
									
										
										
										
											2016-04-03 20:30:37 +01:00
										 |  |  |         transfer to * | 
					
						
							| 
									
										
										
										
											2016-08-22 07:47:03 +01:00
										 |  |  |         transfer to 2001:500:8f::53 | 
					
						
							| 
									
										
										
										
											2016-04-03 20:30:37 +01:00
										 |  |  |     } | 
					
						
							| 
									
										
										
										
											2017-09-15 23:49:20 +01:00
										 |  |  |     errors | 
					
						
							|  |  |  |     log | 
					
						
							| 
									
										
										
										
											2017-01-22 08:14:48 +00:00
										 |  |  | } | 
					
						
							|  |  |  | ~~~ | 
					
						
							| 
									
										
										
										
											2016-08-22 07:47:03 +01:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-08-07 13:24:09 -07:00
										 |  |  | IP addresses are also allowed. They are automatically converted to reverse zones: | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-10-10 09:39:35 +02:00
										 |  |  | ~~~ corefile | 
					
						
							| 
									
										
										
										
											2017-08-07 13:24:09 -07:00
										 |  |  | 10.0.0.0/24 { | 
					
						
							| 
									
										
										
										
											2017-10-10 09:39:35 +02:00
										 |  |  |     whoami | 
					
						
							| 
									
										
										
										
											2017-08-07 13:24:09 -07:00
										 |  |  | } | 
					
						
							|  |  |  | ~~~ | 
					
						
							| 
									
										
										
										
											2017-09-15 23:49:20 +01:00
										 |  |  | Means you are authoritative for `0.0.10.in-addr.arpa.`. | 
					
						
							| 
									
										
										
										
											2017-08-07 13:24:09 -07:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-10-24 10:16:03 +01:00
										 |  |  | This also works for IPv6 addresses. If for some reason you want to serve a zone named `10.0.0.0/24` | 
					
						
							|  |  |  | add the closing dot: `10.0.0.0/24.` as this also stops the conversion. | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | This even works for CIDR (See RFC 1518 and 1519) addressing, i.e `10.0.0.0/25`, CoreDNS will then | 
					
						
							|  |  |  | check if the `in-addr` request falls in the correct range. | 
					
						
							| 
									
										
										
										
											2017-08-07 13:24:09 -07:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-03-13 20:24:37 +00:00
										 |  |  | Listening on TLS and for gRPC? Use: | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-10-10 09:39:35 +02:00
										 |  |  | ~~~ corefile | 
					
						
							| 
									
										
										
										
											2017-03-13 20:24:37 +00:00
										 |  |  | tls://example.org grpc://example.org { | 
					
						
							| 
									
										
										
										
											2017-10-10 09:39:35 +02:00
										 |  |  |     whoami | 
					
						
							| 
									
										
										
										
											2017-03-13 20:24:37 +00:00
										 |  |  | } | 
					
						
							|  |  |  | ~~~ | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | Specifying ports works in the same way: | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | ~~~ txt | 
					
						
							|  |  |  | grpc://example.org:1443 { | 
					
						
							|  |  |  |     # ... | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | ~~~ | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | When no transport protocol is specified the default `dns://` is assumed. | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-04-27 16:24:00 +01:00
										 |  |  | ## Community
 | 
					
						
							| 
									
										
										
										
											2016-08-19 17:14:17 -07:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-03-29 08:24:08 +00:00
										 |  |  | - Website: <https://coredns.io> | 
					
						
							| 
									
										
										
										
											2017-04-27 16:24:00 +01:00
										 |  |  | - Blog: <https://blog.coredns.io> | 
					
						
							| 
									
										
										
										
											2017-03-29 08:24:08 +00:00
										 |  |  | - Twitter: [@corednsio](https://twitter.com/corednsio) | 
					
						
							|  |  |  | - Github: <https://github.com/coredns/coredns> | 
					
						
							| 
									
										
										
										
											2017-04-27 16:24:00 +01:00
										 |  |  | - Mailing list/group: <coredns-discuss@googlegroups.com> | 
					
						
							|  |  |  | - Slack: #coredns on <https://slack.cncf.io> | 
					
						
							| 
									
										
										
										
											2016-05-03 09:00:25 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-04-24 11:45:47 -04:00
										 |  |  | ## Deployment
 | 
					
						
							| 
									
										
										
										
											2016-05-03 09:00:25 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-04-24 11:45:47 -04:00
										 |  |  | Examples for deployment via systemd and other use cases can be found in the | 
					
						
							|  |  |  | [deployment repository](https://github.com/coredns/deployment). |