VinylDNS is a vendor agnostic front-end for enabling self-service DNS and streamlining DNS operations. VinylDNS manages millions of DNS records supporting thousands of engineers in production at Comcast. The platform provides fine-grained access controls, auditing of all changes, a self-service user interface, secure RESTful API, and integration with infrastructure automation tools like Ansible and Terraform. It is designed to integrate with your existing DNS infrastructure, and provides extensibility to fit your installation.
VinylDNS helps secure DNS management via:
- AWS Sig4 signing of all messages to ensure that the message that was sent was not altered in transit
- Throttling of DNS updates to rate limit concurrent updates against your DNS systems
- Encrypting user secrets and TSIG keys at rest and in-transit
- Recording every change made to DNS records and zones
Integration is simple with first-class language support including:
- java
- ruby
- python
- go-lang
- Quickstart
- Code of Conduct
- Developer Guide
- Contributing
- Roadmap
- Contact
- Maintainers and Contributors
- Credits
Docker images for VinylDNS live on Docker Hub at https://hub.docker.com/u/vinyldns/dashboard/. To start up a local instance of VinylDNS on your machine with docker:
- Ensure that you have docker and docker-compose
- Clone the repo:
git clone https://github.com/vinyldns/vinyldns.git
- Navigate to repo:
cd vinyldns
- Run
bin/docker-up-vinyldns.sh
. This will start up the api atlocalhost:9000
and the portal atlocalhost:9001
along with their dependencies, ping the API onhttp://localhost:9000/ping
and the portal onhttp://localhost:9001
, and notify you if either failed to start. - To stop the local setup, run
./bin/remove-vinyl-containers.sh
from the project root.
Things to try after VinylDNS is running:
- View the portal at http://localhost:9001 in a web browser
- Login with the credentials testuser and testpassword
- Navigate to the
groups
tab: http://localhost:9001/groups - Click on the New Group button and create a new group
- Navigate to the
zones
tab: http://localhost:9001/zones - Click on the Connect button to connect to zone, the
bin/docker-up-vinyldns.sh
started up a local bind9 DNS server with a few test zones preloaded, connect toZone Name = dummy.
,Email = [email protected]
,Admin Group = the group you just created
. The DNS Server and Zone Transfer Server can be left blank as the test zones use the defaults - This is async, so refresh the zones page to view the newly created zone
- Click the View button under the Actions column for the
dummy.
zone - You will see that some records are preloaded already, this is because these records existed in the bind9 server and VinylDNS automatically syncs records with the backend DNS server upon zone connection
- From here, you can create DNS record sets in the Manage Records tab, and manage zone settings and ACL rules in the Manage Zone tab
- To try creating a DNS record, click on the Create Record Set button under Records,
Record Type = A, Record Name = my-test-a, TTL = 300, IP Addressess = 1.1.1.1
- Click on the Refresh button under Records, you should see your new record created
Things to note:
- Upon connecting to a zone for the first time, a zone sync is ran to provide VinylDNS a copy of the records in the zone
- Changes made via VinylDNS are made against the DNS backend, you do not need to sync the zone further to push those changes out
- If changes to the zone are made outside of VinylDNS, then the zone will have to be re-synced to give VinylDNS a copy of those records
- If you wish to modify the url used in the creation process from
http://localhost:9000
, to sayhttp://vinyldns.yourdomain.com:9000
, you can modify the bin/.env file before execution. - A similar docker/.env can be modified to change the default ports for the Portal and API. You must also modify their config files with the new port: https://www.vinyldns.io/operator/config-portal & https://www.vinyldns.io/operator/config-api
For details regarding setup and configuration of the dev environment, see the Developer Guide.
This project and everyone participating in it are governed by the VinylDNS Code Of Conduct. By participating, you agree to this Code. Please report any violations to the code of conduct to [email protected].
See DEVELOPER_GUIDE.md for instructions on setting up VinylDNS locally.
See the Contributing Guide.
See ROADMAP.md for the future plans for VinylDNS.
- Gitter
- Mailing List
- If you have any security concerns please contact the maintainers directly [email protected]
The current maintainers (people who can merge pull requests) are:
- Paul Cleary
- Nima Eskandary
- Michael Ly
- Rebecca Star
- Britney Wright
See AUTHORS.md for the full list of contributors to VinylDNS.
See MAINTAINERS.md for documentation specific to maintainers
VinylDNS would not be possible without the help of many other pieces of open source software. Thank you open source world!
Initial development of DynamoDBHelper done by Roland Kuhn from https://github.com/akka/akka-persistence-dynamodb/blob/8d7495821faef754d97759f0d3d35ed18fc17cc7/src/main/scala/akka/persistence/dynamodb/journal/DynamoDBHelper.scala
Given the Apache 2.0 license of VinylDNS, we specifically want to call out the following libraries and their corresponding licenses shown below.