Releases: farshidmousavii/sentrydns
Releases · farshidmousavii/sentrydns
Release list
v1.2.0
What's new
- Global QPS cap (
global_qps_limit) — token-bucket limit across all clients, SERVFAIL on exceed. Protects the server and upstreams from floods, forwarding loops, and runaway clients. - Loop detection (
loop_detection, default on) — refuses (REFUSED) queries arriving from configured upstream IPs, breaking forwarding loops. - Prometheus metrics — new
/metrics/promendpoint (Prometheus text format 0.0.4) alongside the existing JSON/metrics. 38 metrics, ready for Grafana. - sentrydps v1.1.0 — new
LOOP_DETECTEDandGLOBAL_LIMIT_HITprobe alerts. - New counters:
queries_global_limited,loop_detections.
Deploy
make deploy SERVER=user@serverSee README for full config reference (config.example.yaml).
v1.1.0
What's new
- Static A records — new
static_recordsconfig option answers A queries for pinned domains directly from memory, bypassing upstreams entirely. Exact FQDN match only; AAAA and other query types take the normal routing path. - Fix: static records win over cached answers — static lookup now runs before the cache, so a pinned
static_recordsentry can never be shadowed by a previously learned answer still in the TTL cache. - New
path_staticmetric (/metrics).
Example
static_records:
"internal.example.com": "10.0.0.5"
"vpn.example.com": "192.168.1.10"Assets
sentrydns— DNS proxy binary (Linux amd64)sentrydns-v1.1.0.tar.gz— binary + systemd services + install/uninstall scripts + config
v1.0.0 — Initial Production Release
SentryDNS v1.0.0
Adaptive split-DNS proxy with IP classification, hijack detection, and learned routing — zero manual domain management.
Quick Install
wget https://github.com/farshidmousavii/sentrydns/releases/download/v1.0.0/sentrydns-v1.0.0.tar.gz
tar xzf sentrydns-v1.0.0.tar.gz
sudo bash install.shWhat's Inside
| File | Description |
|---|---|
sentrydns |
DNS proxy binary (Linux amd64) |
sentrydns.service |
systemd unit for the DNS proxy |
sentrydps.service |
systemd unit for diagnostic probing |
install.sh |
Automated installer (copies files, sets up services) |
uninstall.sh |
Clean removal script |
sentrydps.sh |
Diagnostic probe script |
config.example.yaml |
Full configuration reference |
Features
- Adaptive routing — Learns whether each domain should use IranDNS or GlobalDNS.
- Hijack detection — Identifies poisoned DNS responses from upstream.
- Circuit breaker — Automatically skips degraded upstreams.
- Short-wait optimization — Parallel DNS queries with adaptive timeout.
- Cleanup engine — Periodic stale-domain eviction with health gating.
- Rate limiting — Per-IP rate limiter with configurable QPS.
- Observability
- Metrics endpoint (JSON)
- Diagnostic probe (
sentrydps) - Structured logging via
journald
Changelog
149 commits, including:
- Core resolver, cache, and learning engine
- Circuit breaker with half-open recovery and decay
- Rate limiter, cleanup scheduler, and store persistence
- Metrics system:
- Total queries
- IranDNS queries
- GlobalDNS queries
- SERVFAIL responses
- Cache hit rates
- Circuit breaker statistics
- Diagnostic probe (
sentrydps) with threshold alerting - Farsi & English architecture documentation
- Production hardening:
- Graceful shutdown
- Timer leak fixes
- Data race fixes
- Panic recovery