2019-12-07 08:36:43 +00:00
|
|
|
# Directives are registered in the order they should be executed.
|
2017-01-31 12:25:02 -05:00
|
|
|
#
|
2019-12-07 08:36:43 +00:00
|
|
|
# Ordering is VERY important. Every plugin will feel the effects of all other
|
|
|
|
|
# plugin below (after) them during a request, but they must not care what plugin
|
|
|
|
|
# above them are doing.
|
2017-01-31 12:25:02 -05:00
|
|
|
|
2019-12-07 08:36:43 +00:00
|
|
|
# How to rebuild with updated plugin configurations: Modify the list below and
|
|
|
|
|
# run `go generate && go build`
|
2017-01-31 12:25:02 -05:00
|
|
|
|
2019-12-07 08:36:43 +00:00
|
|
|
# The parser takes the input format of:
|
|
|
|
|
#
|
2017-10-16 10:49:18 +02:00
|
|
|
# <plugin-name>:<package-name>
|
2017-02-19 20:34:29 +00:00
|
|
|
# Or
|
2017-10-16 10:49:18 +02:00
|
|
|
# <plugin-name>:<fully-qualified-package-name>
|
2017-02-19 20:34:29 +00:00
|
|
|
#
|
2017-09-14 09:36:06 +01:00
|
|
|
# External plugin example:
|
2019-12-07 08:36:43 +00:00
|
|
|
#
|
2017-10-16 10:49:18 +02:00
|
|
|
# log:github.com/coredns/coredns/plugin/log
|
2017-09-14 09:36:06 +01:00
|
|
|
# Local plugin example:
|
2017-10-16 10:49:18 +02:00
|
|
|
# log:log
|
2017-01-31 12:25:02 -05:00
|
|
|
|
2023-12-08 16:50:30 +01:00
|
|
|
root:root
|
2018-06-29 12:44:16 +03:00
|
|
|
metadata:metadata
|
2021-07-14 08:25:30 +01:00
|
|
|
geoip:geoip
|
2019-03-29 19:40:23 +00:00
|
|
|
cancel:cancel
|
2026-03-31 00:43:31 +03:00
|
|
|
proxyproto:proxyproto
|
2025-05-19 03:49:21 +03:00
|
|
|
quic:quic
|
2025-12-18 05:08:59 +02:00
|
|
|
grpc_server:grpc_server
|
|
|
|
|
https:https
|
|
|
|
|
https3:https3
|
2022-12-28 11:14:16 +00:00
|
|
|
timeouts:timeouts
|
2024-11-13 20:40:25 +03:00
|
|
|
multisocket:multisocket
|
2018-03-02 17:17:26 -08:00
|
|
|
reload:reload
|
2017-12-04 08:28:27 -08:00
|
|
|
nsid:nsid
|
2019-11-10 08:10:12 +00:00
|
|
|
bufsize:bufsize
|
2017-10-16 10:49:18 +02:00
|
|
|
bind:bind
|
|
|
|
|
debug:debug
|
|
|
|
|
trace:trace
|
2019-03-07 20:35:16 +00:00
|
|
|
ready:ready
|
2017-10-16 10:49:18 +02:00
|
|
|
health:health
|
|
|
|
|
pprof:pprof
|
plugin/shed: add UDP overload protection plugin (#8312)
* plugin/shed: add UDP overload protection plugin
UDP responses written back through one listener socket serialize on the
Go runtime's internal fdMutex, which allows at most 2^20-1 concurrent
operations per file descriptor and panics the process when exceeded.
CoreDNS serves UDP with one goroutine per query, all writing through the
shared packet connection, so a sustained overload parks every excess
in-flight query in that wait queue until the process dies with
"too many concurrent operations on a single file or socket". Observed
in production: ~2.8M goroutines and 60GiB RSS before the panic.
The shed plugin makes the panic structurally unreachable. It installs,
via Config.UDPDecorateWriterFunc, a per-socket bounded evict-oldest
stack drained newest-first by a single writer goroutine, so the fd
never sees more than one writer and residual capacity under overload
always goes to the freshest response. While a socket's stack is full,
arriving queries are dropped before any plugin runs. Drops are silent
(the client's resolver retries elsewhere) and counted in
coredns_shed_dropped_total{server, reason}.
plugin/shed/fdmutex_test.go demonstrates the failure and the fix with
one shared flood harness. Two subprocess tests reproduce the exact
runtime panic without the plugin's write discipline - one deterministic
(a held write plus >2^20 queued writers), one with nothing held or
mocked; both exercise the Go runtime rather than the plugin, so they
are gated behind SHED_FLOOD_TEST=1. The counterfactual - the same load
through the plugin's stack, completing with every response accounted
for as written or dropped - runs in every test invocation, including
-race, at 50k responders, and at the full 1.5M with SHED_FLOOD_TEST=1:
SHED_FLOOD_TEST=1 go test ./plugin/shed/
Signed-off-by: Ryan Brewster <rpb@anthropic.com>
* test: add shed e2e test
Query a shed-enabled server over UDP (the plugin's deferred
single-writer path) and TCP (which shed passes through), and check
that coredns_shed_dropped_total is exported with its reason label.
No-Verification-Needed: test-only change
Signed-off-by: Ryan Brewster <rpb@anthropic.com>
---------
Signed-off-by: Ryan Brewster <rpb@anthropic.com>
2026-07-27 05:13:25 -04:00
|
|
|
shed:shed
|
2017-10-16 10:49:18 +02:00
|
|
|
prometheus:metrics
|
|
|
|
|
errors:errors
|
|
|
|
|
log:log
|
|
|
|
|
dnstap:dnstap
|
2020-11-05 15:02:07 +01:00
|
|
|
local:local
|
2020-03-26 08:42:23 +01:00
|
|
|
dns64:dns64
|
2019-04-28 11:46:45 +01:00
|
|
|
any:any
|
2017-10-16 10:49:18 +02:00
|
|
|
chaos:chaos
|
2018-01-11 19:59:56 +01:00
|
|
|
loadbalance:loadbalance
|
2022-06-27 15:48:34 -04:00
|
|
|
tsig:tsig
|
2017-10-16 10:49:18 +02:00
|
|
|
rewrite:rewrite
|
2026-07-14 22:36:06 -07:00
|
|
|
autopath:autopath
|
2026-02-25 10:19:47 +00:00
|
|
|
acl:acl
|
2026-07-14 22:26:49 -07:00
|
|
|
cache:cache
|
2021-07-15 09:32:39 +02:00
|
|
|
header:header
|
2017-10-16 10:49:18 +02:00
|
|
|
dnssec:dnssec
|
2026-07-30 10:24:22 +08:00
|
|
|
# Keep tls here so dnssec can sign ACME challenge records before authoritative backends run.
|
|
|
|
|
tls:tls
|
2021-03-15 20:07:55 +05:30
|
|
|
minimal:minimal
|
2018-01-08 11:52:25 +01:00
|
|
|
template:template
|
2019-11-01 12:02:43 -04:00
|
|
|
transfer:transfer
|
2017-10-16 10:49:18 +02:00
|
|
|
hosts:hosts
|
2018-01-15 09:59:29 -08:00
|
|
|
route53:route53
|
2019-08-09 12:40:28 +05:30
|
|
|
azure:azure
|
2019-08-18 02:29:09 +05:30
|
|
|
clouddns:clouddns
|
2018-12-14 09:41:51 +00:00
|
|
|
k8s_external:k8s_external
|
2017-10-16 10:49:18 +02:00
|
|
|
kubernetes:kubernetes
|
|
|
|
|
file:file
|
|
|
|
|
auto:auto
|
|
|
|
|
secondary:secondary
|
|
|
|
|
etcd:etcd
|
2018-07-20 19:45:17 +01:00
|
|
|
loop:loop
|
2018-02-05 22:00:47 +00:00
|
|
|
forward:forward
|
2019-03-14 08:12:28 +01:00
|
|
|
grpc:grpc
|
2017-10-16 10:49:18 +02:00
|
|
|
erratic:erratic
|
|
|
|
|
whoami:whoami
|
2020-09-24 18:14:41 +02:00
|
|
|
on:github.com/coredns/caddy/onevent
|
2019-08-29 15:41:59 +01:00
|
|
|
sign:sign
|
2022-09-08 14:56:27 -04:00
|
|
|
view:view
|
2025-09-30 18:35:32 +02:00
|
|
|
nomad:nomad
|