Repository navigation
Releases: mrcdlm/dnsdeck
Release list
dnsdeck v0.5.0
Added
TRUSTED_PROXIES: behind a reverse proxy or Cloudflare Tunnel, the real client address is taken fromCF-Connecting-IP/X-Forwarded-For– for the login rate limit and logs. Before, failed logins of one client blocked everyone behind the same proxy. The headers are only trusted from the configured proxies.- Reachability checks keep a 30-day history, shown as uptime bars (24 hours / 7 days) on the Reachability page.
- Expected status per check (e.g.
200,2xx,200-399): only these codes count as reachable. Checks can now be edited (address and expected status).
Security
- Cross-site request forgery: write requests to the API are only accepted from dnsdeck's own origin. Before, a page on a sibling subdomain of the same domain could, for example, create a webhook and thereby read webhook secrets, despite the
SameSite=Strictcookie. - Login rate limit: attempts are counted before the password check, so parallel requests can no longer exceed the limit of 10 attempts per minute.
- Changing
APP_PASSWORDnow signs out all existing sessions. After updating, everyone has to sign in once again.
Install or update
Image: ghcr.io/mrcdlm/dnsdeck:0.5.0 (linux/amd64, linux/arm64)
Set DNSDECK_VERSION=0.5.0 in .env, then run:
docker compose pull && docker compose up -dNew here? Start with the quick start.
Full Changelog: v0.4.0...v0.5.0
dnsdeck v0.4.0
Added
- Speed test: download, upload, ping and jitter measured against the nearest Cloudflare data center (
speed.cloudflare.com), on demand or on a schedule (off by default, 1 h – 7 days). New page with history chart and table, dashboard tile, data center and location per result.
Install or update
Image: ghcr.io/mrcdlm/dnsdeck:0.4.0 (linux/amd64, linux/arm64)
Set DNSDECK_VERSION=0.4.0 in .env, then run:
docker compose pull && docker compose up -dNew here? Start with the quick start.
Full Changelog: v0.3.2...v0.4.0
dnsdeck v0.3.2
Changed
- Docker Compose: the container drops all Linux capabilities and runs with
no-new-privileges(dnsdeck needs neither). If you use your owndocker-compose.yml, addcap_drop: [ALL]andsecurity_opt: [no-new-privileges:true]belowrestart:. - A warning is logged on start if a plain-text
APP_PASSWORDis shorter than 12 characters. - Updated screenshots; contribution guide and issue templates.
- GitHub releases show the changes from this changelog instead of a generic text.
Install or update
Image: ghcr.io/mrcdlm/dnsdeck:0.3.2 (linux/amd64, linux/arm64)
Set DNSDECK_VERSION=0.3.2 in .env, then run:
docker compose pull && docker compose up -dNew here? Start with the quick start.
Full Changelog: v0.3.1...v0.3.2
dnsdeck v0.3.1
Fixed
- Connection errors to Cloudflare are shown as a short message (e.g. “Cloudflare did not respond in time”) instead of the raw Go error with the full request URL; entries already stored are shortened when displayed.
- Long messages in the update log, history, records and reachability checks wrap instead of overflowing their card.
Install or update
Image: ghcr.io/mrcdlm/dnsdeck:0.3.1 (linux/amd64, linux/arm64)
Set DNSDECK_VERSION=0.3.1 in .env, then run:
docker compose pull && docker compose up -dNew here? Start with the quick start.
dnsdeck v0.3.0
Added
- Installable as an app (PWA): web app manifest, icons and a service worker. The interface also opens offline; API data is never cached.
- Blocklist check: the public IPv4 is checked against DNS blocklists (Spamhaus ZEN, SpamCop, PSBL, Mailspike) after every IP change and every 24 hours. The result is shown in the IP card; new listings trigger the new webhook event
blocklist_listed. Spamhaus PBL is shown as information only.DNSBL_LISTSselects the lists or disables the check (off). - Reachability and certificate monitoring: new page Reachability checks your own services over HTTP(S) – per record with a switch in the record dialog, or any URL. Outages are reported after two failures in a row; TLS certificates are verified (expiry, host name, issuer) with a warning before they expire (default 14 days). New webhook events
site_down,site_recoveredandcert_expiring; check interval and warning period under Settings.
Install or update
Image: ghcr.io/mrcdlm/dnsdeck:0.3.0 (linux/amd64, linux/arm64)
Set DNSDECK_VERSION=0.3.0 in .env, then run:
docker compose pull && docker compose up -dNew here? Start with the quick start.
dnsdeck v0.2.2
Added
- The dashboard shows the internet provider of each public address: AS number and name, country, network and reverse DNS name. Looked up via DNS at Team Cymru (no API key);
ISP_LOOKUP=offdisables it.
Install or update
Image: ghcr.io/mrcdlm/dnsdeck:0.2.2 (linux/amd64, linux/arm64)
Set DNSDECK_VERSION=0.2.2 in .env, then run:
docker compose pull && docker compose up -dNew here? Start with the quick start.
dnsdeck v0.2.1
Fixed
- The sidebar (live status, language, theme, sign out) stays visible on long pages instead of scrolling away.
- Update log and record messages written before 0.2.0 are now translated as well: known German texts are converted once on start.
Install or update
Image: ghcr.io/mrcdlm/dnsdeck:0.2.1 (linux/amd64, linux/arm64)
Set DNSDECK_VERSION=0.2.1 in .env, then run:
docker compose pull && docker compose up -dNew here? Start with the quick start.
dnsdeck v0.2.0
Added
- English web interface: the language follows the browser and can be switched (EN | DE); server messages (errors, record status, update log) are translated as well.
- Setting for the language of notifications (default German).
- DNS propagation status per record: public resolvers and the zone's authoritative name servers are checked automatically after every change and on demand. Configurable with
DNSCHECK_RESOLVERSandDNSCHECK_AUTHORITATIVE. - Light mode: the appearance follows the system setting or can be set to light or dark.
Changed
- Docker Compose: the image version is pinned via
DNSDECK_VERSIONin.env(required, nolatest); host port (DNSDECK_PORT) and time zone (TZ, defaultUTC) are configurable. - Documentation in English and German, MIT license.
Install or update
Image: ghcr.io/mrcdlm/dnsdeck:0.2.0 (linux/amd64, linux/arm64)
Set DNSDECK_VERSION=0.2.0 in .env, then run:
docker compose pull && docker compose up -dNew here? Start with the quick start.
dnsdeck v0.1.0
First public release.
Added
- Public IPv4/IPv6 detection from several sources with majority vote and plausibility checks.
- Dynamic DNS for Cloudflare A and AAAA records: only updates on differences, creates missing records, adopts existing ones with their proxy/TTL settings.
- Cloudflare Tunnel monitoring with status history and 24 h / 7 day uptime.
- Live web interface (Server-Sent Events): dashboard, records, tunnels, history, settings.
- Configurable webhooks with templates for ntfy, Gotify, Discord, Slack, Telegram and Home Assistant; secrets referenced from environment variables.
- Single-container deployment (distroless, non-root, amd64 and arm64) published to ghcr.io.
Install or update
Image: ghcr.io/mrcdlm/dnsdeck:0.1.0 (linux/amd64, linux/arm64)
Set DNSDECK_VERSION=0.1.0 in .env, then run:
docker compose pull && docker compose up -dNew here? Start with the quick start.