unbound: Use Google as external resolver

This commit is contained in:
Timo Makinen 2024-10-12 18:09:09 +00:00
parent 13840dd12a
commit 58bde398c0
2 changed files with 12 additions and 2 deletions

View file

@ -8,7 +8,7 @@ server:
tls-service-key: {{ tls_private }}/dns.home.foo.sh.key tls-service-key: {{ tls_private }}/dns.home.foo.sh.key
tls-service-pem: {{ tls_certs }}/dns.home.foo.sh.crt tls-service-pem: {{ tls_certs }}/dns.home.foo.sh.crt
tls-cert-bundle: {{ tls_certs }}/ca.crt tls-cert-bundle: {{ tls_bundle }}
access-control: 127.0.0.0/8 allow access-control: 127.0.0.0/8 allow
access-control: ::1 allow access-control: ::1 allow
@ -26,6 +26,11 @@ remote-control:
control-enable: yes control-enable: yes
control-interface: /var/run/unbound.sock control-interface: /var/run/unbound.sock
forward-zone:
name: "."
forward-tls-upstream: yes
forward-addr: 8.8.8.8@853#dns.google
{% for zone in unbound_zones %} {% for zone in unbound_zones %}
auth-zone: auth-zone:
name: "{{ zone }}" name: "{{ zone }}"

View file

@ -8,7 +8,7 @@ server:
tls-service-key: {{ tls_private }}/dns.home.foo.sh.key tls-service-key: {{ tls_private }}/dns.home.foo.sh.key
tls-service-pem: {{ tls_certs }}/dns.home.foo.sh.crt tls-service-pem: {{ tls_certs }}/dns.home.foo.sh.crt
tls-cert-bundle: {{ tls_certs }}/ca.crt tls-cert-bundle: {{ tls_bundle }}
access-control: 127.0.0.0/8 allow access-control: 127.0.0.0/8 allow
access-control: ::1 allow access-control: ::1 allow
@ -26,6 +26,11 @@ remote-control:
control-enable: yes control-enable: yes
control-interface: /var/run/unbound.sock control-interface: /var/run/unbound.sock
forward-zone:
name: "."
forward-tls-upstream: yes
forward-addr: 8.8.8.8@853#dns.google
{% for zone in unbound_zones %} {% for zone in unbound_zones %}
auth-zone: auth-zone:
name: "{{ zone }}" name: "{{ zone }}"