Skip to content

Releases: farshidmousavii/sentrydns

v1.2.0

Choose a tag to compare

@farshidmousavii farshidmousavii released this 15 Aug 09:59

What's new

  • Global QPS cap (global_qps_limit) — token-bucket limit across all clients, SERVFAIL on exceed. Protects the server and upstreams from floods, forwarding loops, and runaway clients.
  • Loop detection (loop_detection, default on) — refuses (REFUSED) queries arriving from configured upstream IPs, breaking forwarding loops.
  • Prometheus metrics — new /metrics/prom endpoint (Prometheus text format 0.0.4) alongside the existing JSON /metrics. 38 metrics, ready for Grafana.
  • sentrydps v1.1.0 — new LOOP_DETECTED and GLOBAL_LIMIT_HIT probe alerts.
  • New counters: queries_global_limited, loop_detections.

Deploy

make deploy SERVER=user@server

See README for full config reference (config.example.yaml).

v1.1.0

Choose a tag to compare

@farshidmousavii farshidmousavii released this 11 Aug 10:43

What's new

  • Static A records — new static_records config option answers A queries for pinned domains directly from memory, bypassing upstreams entirely. Exact FQDN match only; AAAA and other query types take the normal routing path.
  • Fix: static records win over cached answers — static lookup now runs before the cache, so a pinned static_records entry can never be shadowed by a previously learned answer still in the TTL cache.
  • New path_static metric (/metrics).

Example

static_records:
  "internal.example.com": "10.0.0.5"
  "vpn.example.com": "192.168.1.10"

Assets

  • sentrydns — DNS proxy binary (Linux amd64)
  • sentrydns-v1.1.0.tar.gz — binary + systemd services + install/uninstall scripts + config

v1.0.0 — Initial Production Release

Choose a tag to compare

@farshidmousavii farshidmousavii released this 21 Jul 09:18

SentryDNS v1.0.0

Adaptive split-DNS proxy with IP classification, hijack detection, and learned routing — zero manual domain management.

Quick Install

wget https://github.com/farshidmousavii/sentrydns/releases/download/v1.0.0/sentrydns-v1.0.0.tar.gz
tar xzf sentrydns-v1.0.0.tar.gz
sudo bash install.sh

What's Inside

File Description
sentrydns DNS proxy binary (Linux amd64)
sentrydns.service systemd unit for the DNS proxy
sentrydps.service systemd unit for diagnostic probing
install.sh Automated installer (copies files, sets up services)
uninstall.sh Clean removal script
sentrydps.sh Diagnostic probe script
config.example.yaml Full configuration reference

Features

  • Adaptive routing — Learns whether each domain should use IranDNS or GlobalDNS.
  • Hijack detection — Identifies poisoned DNS responses from upstream.
  • Circuit breaker — Automatically skips degraded upstreams.
  • Short-wait optimization — Parallel DNS queries with adaptive timeout.
  • Cleanup engine — Periodic stale-domain eviction with health gating.
  • Rate limiting — Per-IP rate limiter with configurable QPS.
  • Observability
    • Metrics endpoint (JSON)
    • Diagnostic probe (sentrydps)
    • Structured logging via journald

Changelog

149 commits, including:

  • Core resolver, cache, and learning engine
  • Circuit breaker with half-open recovery and decay
  • Rate limiter, cleanup scheduler, and store persistence
  • Metrics system:
    • Total queries
    • IranDNS queries
    • GlobalDNS queries
    • SERVFAIL responses
    • Cache hit rates
    • Circuit breaker statistics
  • Diagnostic probe (sentrydps) with threshold alerting
  • Farsi & English architecture documentation
  • Production hardening:
    • Graceful shutdown
    • Timer leak fixes
    • Data race fixes
    • Panic recovery