As part of setting up my Kubernetes cluster, I wanted to setup a private DNS, for my private internal (to my LAN) domain.
To do that, I needed to first setup a DNS server with bind9. I did that on the node that I’m using as my home NAS, which I’d later assign as the CA certificate issuer and k8s controller for my cluster.
Install bind9
Since I was using Ubuntu, their DNS server guide came in handy. To install bind9, all I did was:
sudo apt install -y bind9Domain Configuration
named.conf.local
To setup my domain, which I’d decided I’ll name k0r0pt.int, I had to first configure /etc/bind/named.conf.local to have a Zone entry for it. So I just spun up vim on the config:
sudo vim /etc/bind/named.conf.localAnd this is what it looked like after I was done editing it:
#//
#// Do any local configuration here
#//
#// Consider adding the 1918 zones here, if they are not used in your
#// organization
#//include "/etc/bind/zones.rfc1918";
zone "k0r0pt.int" {
type master;
file "/etc/bind/db.k0r0pt.int";
};named.conf.options
Next order of business was to ensure that if my DNS server doesn’t know the answer to a query, it can ask another upstream DNS server. This will come in handy, when querying for anything that isn’t a domain that this server is managing the DNS records for. For that, I’d need to add forwarders to /etc/bind/named.conf.options.
sudo vim /etc/bind/named.conf.optionsHere’s what it looked like after I was done:
options {
directory "/var/cache/bind";
// If there is a firewall between you and nameservers you want
// to talk to, you may need to fix the firewall to allow multiple
// ports to talk. See http://www.kb.cert.org/vuls/id/800113
// If your ISP provided one or more IP addresses for stable
// nameservers, you probably want to use them as forwarders.
// Uncomment the following block, and insert the addresses replacing
// the all-0's placeholder.
forwarders {
1.1.1.1;
8.8.8.8;
8.8.4.4;
};
//========================================================================
// If BIND logs error messages about the root key being expired,
// you will need to update your keys. See https://www.isc.org/bind-keys
//========================================================================
dnssec-validation auto;
auth-nxdomain no;
listen-on-v6 { any; };
};db.k0r0pt.int
For the zone I defined in named.conf.local, I then needed to setup the db.k0r0pt.int file. I just copied the one for the loopback interface, and edited it to what I wanted.
sudo cp /etc/bind/db.127 /etc/bind/db.k0r0pt.int
sudo vim /etc/bind/db.k0r0pt.intThis is what it looked like when I was done:
;
; BIND data file for k0r0pt.int
;
$TTL 604800
@ IN SOA ns.k0r0pt.int. root.k0r0pt.int. (
2013012110 ; Serial
604800 ; Refresh
86400 ; Retry
2419200 ; Expire
604800 ) ; Negative Cache TTL
;
@ IN NS ns.k0r0pt.int.
ns IN A 192.168.1.230
server IN A 192.168.1.230
www IN A 192.168.1.230
* IN A 192.168.1.231
* IN A 192.168.1.232
* IN A 192.168.1.233
ca IN A 192.168.1.230Notice how the A record for ca is pointing to one address. Everything other than ns, server, www and ca is pointing to 3 alternatives. These 3 nodes are going to be my k8s worker nodes, and I’ll be setting Ingress controllers for hostnames, that will point to those nodes.
Restart the bind9 service
Once done with the changes, all I had to do was restart the bind9 server for them to take effect.
sudo service bind9 restartAnd then verify that everything was going to be okay.
sudo service bind9 statusTesting if the changes work
To test that we’re golden, all I had to do was do a lookup.
xtreme@k0r0ptnas:~$ nslookup
> server 127.0.0.1
Default server: 127.0.0.1
Address: 127.0.0.1#53
> ca.k0r0pt.int
Server: 127.0.0.1
Address: 127.0.0.1#53
Name: ca.k0r0pt.int
Address: 192.168.1.230
>