Repository navigation
Releases: skitzo2000/espdns
Releases · skitzo2000/espdns
Release list
espDNS 0.0.1
The first numbered version: everything built so far, from the node firmware and the
controller's first pages to the security review's fixes and the backend of the redesigned GUI.
Added
- Versions: the repository's
VERSIONis the firmware's version (its app descriptor's, so
/status, the image header and the controller say it, no longergit describe) and the
controller's (espdns version,/api/session, its log). Firmware updates are ordered by
version, the build time breaking a tie between two builds of one version.
scripts/bump-version.shmoves to the next version. - The node: a small OS on ESP32-P4 and ESP32-S3 boards (wired Ethernet, Wi-Fi as a fallback,
microSD): the services its config enables (hosted zones, secondary zones over AXFR,
forwarding, a cache, blocking, a query log), board definitions as data, a memory plan from
board data, health states and LEDs,/status,/metricsand the query log with a cursor.
It takes only signed releases (ECDSA P-256, bound to the node, board and a sequence number). - Blocking: lists compiled by the controller (adblock, hosts, domains, wildcard and RPZ
sources, allow lists, overrides), placed in the node's memory tiers, with a size-change
check, a list canary, a soak and a revert to the older list the node keeps. - The controller (one Go binary with a web UI, run with Docker Compose) and its CLI
(espdns): discovery, adoption, node configs and their editor, the zone editor, any zone
primary (manual, or Technitium's API as a driver), rolling pushes that never take down the
last healthy node, a dashboard and the query log, backup, restore and recovery from the
nodes. - The GUI's backend for the redesign: zone inventory and zone lookup; pending changes and
one apply job that sends them; the node settings form, its edits as pending changes;
firmware update availability, shown as versions; one search across nodes, zones and
lists; the first run andsettings.jsonfrom the browser; and looking up a node to add
by its address. - Forwarding: a table of the upstream queries in flight, with caps per group.
- Hosted zones: a revert to the older bundle the node keeps, from the firmware, the CLI, make,
a controller job and the Zones page.
Changed
- Hosted zones are held in canonical order, with a binary search for a name's existence, and
to their memory limit; an AXFR and its SOA check run within one deadline. - The test vectors, fixtures and tests use documentation addresses and names only, and CI
refuses private ones.
Security
- The controller loads esp-web-tools from its own vendored copy (10.4.0), not from a CDN.
- The controller sends a strict Content Security Policy and security headers on every
response, with no inline scripts. - Firmware builds: no key and no network in the build containers, signing in a step of its
own, and container images and CI actions pinned by digest. - The node's HTTP server checks the Host header against DNS rebinding, gives each request one
deadline, applies releases in a worker, and JSON-escapes/status. - Controller sessions are bound to the page's origin, logins back off per client, and a backup
or a revealed Wi-Fi password asks for the password again. - The controller's data directory is the user's only (directories 0700, files 0600), and its
container is hardened: no capabilities, no new privileges, a read-only root, memory and
process limits.
Every file is listed in SHA256SUMS, signed with the espDNS release key in SHA256SUMS.sig:
check them before use as docs/releasing.md, Checking a release, says.