As part of setting up my Kubernetes cluster, I wanted to setup a private DNS, for my private internal (to my LAN) domain.

To do that, I needed to first setup a DNS server with bind9. I did that on the node that I’m using as my home NAS, which I’d later assign as the CA certificate issuer and k8s controller for my cluster.


Install bind9

Since I was using Ubuntu, their DNS server guide came in handy. To install bind9, all I did was:

sudo apt install -y bind9

Domain Configuration

named.conf.local

To setup my domain, which I’d decided I’ll name k0r0pt.int, I had to first configure /etc/bind/named.conf.local to have a Zone entry for it. So I just spun up vim on the config:

sudo vim /etc/bind/named.conf.local

And this is what it looked like after I was done editing it:

#//
#// Do any local configuration here
#//
 
#// Consider adding the 1918 zones here, if they are not used in your
#// organization
#//include "/etc/bind/zones.rfc1918";
zone "k0r0pt.int" {
  type master;
  file "/etc/bind/db.k0r0pt.int";
};

named.conf.options

Next order of business was to ensure that if my DNS server doesn’t know the answer to a query, it can ask another upstream DNS server. This will come in handy, when querying for anything that isn’t a domain that this server is managing the DNS records for. For that, I’d need to add forwarders to /etc/bind/named.conf.options.

sudo vim /etc/bind/named.conf.options

Here’s what it looked like after I was done:

options {
  directory "/var/cache/bind";
 
  // If there is a firewall between you and nameservers you want
  // to talk to, you may need to fix the firewall to allow multiple
  // ports to talk.  See http://www.kb.cert.org/vuls/id/800113
 
  // If your ISP provided one or more IP addresses for stable
  // nameservers, you probably want to use them as forwarders.
  // Uncomment the following block, and insert the addresses replacing
  // the all-0's placeholder.
 
  forwarders {
    1.1.1.1;
    8.8.8.8;
    8.8.4.4;
  };
 
  //========================================================================
  // If BIND logs error messages about the root key being expired,
  // you will need to update your keys.  See https://www.isc.org/bind-keys
  //========================================================================
  dnssec-validation auto;
  auth-nxdomain no;
  listen-on-v6 { any; };
};

db.k0r0pt.int

For the zone I defined in named.conf.local, I then needed to setup the db.k0r0pt.int file. I just copied the one for the loopback interface, and edited it to what I wanted.

sudo cp /etc/bind/db.127 /etc/bind/db.k0r0pt.int
sudo vim /etc/bind/db.k0r0pt.int

This is what it looked like when I was done:

;
; BIND data file for k0r0pt.int
;
$TTL    604800
@       IN      SOA     ns.k0r0pt.int. root.k0r0pt.int. (
                 2013012110         ; Serial
                     604800         ; Refresh
                      86400         ; Retry
                    2419200         ; Expire
                     604800 )       ; Negative Cache TTL
;
@       IN      NS      ns.k0r0pt.int.
ns      IN      A       192.168.1.230
server  IN      A       192.168.1.230
www     IN      A       192.168.1.230
*       IN      A       192.168.1.231
*       IN      A       192.168.1.232
*       IN      A       192.168.1.233
ca      IN      A       192.168.1.230

Notice how the A record for ca is pointing to one address. Everything other than ns, server, www and ca is pointing to 3 alternatives. These 3 nodes are going to be my k8s worker nodes, and I’ll be setting Ingress controllers for hostnames, that will point to those nodes.

Restart the bind9 service

Once done with the changes, all I had to do was restart the bind9 server for them to take effect.

sudo service bind9 restart

And then verify that everything was going to be okay.

sudo service bind9 status

Testing if the changes work

To test that we’re golden, all I had to do was do a lookup.

xtreme@k0r0ptnas:~$ nslookup
> server 127.0.0.1
Default server: 127.0.0.1
Address: 127.0.0.1#53
> ca.k0r0pt.int
Server:         127.0.0.1
Address:        127.0.0.1#53

Name:   ca.k0r0pt.int
Address: 192.168.1.230
>