bind9.yml 8.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286
  1. ---
  2. # To update DNSSEC keys, see https://www.isc.org/bind-keys
  3. bind:
  4. options:
  5. directory: "/var/cache/bind"
  6. recursion: true
  7. allow_recursion:
  8. - 127.0.0.1
  9. allow_query:
  10. - 127.0.0.1
  11. allow_transfer:
  12. - 127.0.0.1
  13. dnssec_validation: auto
  14. validate_except:
  15. - ff3l
  16. - fffd
  17. - fftr
  18. - ffhl
  19. port: 5353
  20. listen_on:
  21. - any
  22. servers:
  23. - server: 172.22.149.225
  24. keys:
  25. - transfer_key
  26. keys:
  27. - name: transfer_key
  28. algorithm: hmac-sha512
  29. secret: !vault |
  30. $ANSIBLE_VAULT;1.1;AES256
  31. 64643966386533336163363338663333643033633035663265393266333564323062313266363661
  32. 6662313134613662623063623362626662346363623765620a643239396662333533383535613765
  33. 34333631636338353139643163653261653461616165343761393364396462343733346465633463
  34. 6666366535366631350a343232643764343433376261376239333439393931646566613934666533
  35. 30393533356139396666356466643038656566613739666664633433656163303865396332616533
  36. 66316636363931663335636661656365633939313065663632383665353661623764666563666565
  37. 31653861316539326531396161323365333739633833363039663462313335316663376666373234
  38. 63393764386661363837393432653361613666636239366433366562653963333966313563303939
  39. 6630
  40. zones:
  41. # Own zones
  42. ## Clearnet
  43. - zone: mk16.de.
  44. type: slave
  45. file: "/var/cache/bind/db.mk16.de"
  46. masters:
  47. - 172.22.149.225 port 5353
  48. - zone: dn42-lab.de.
  49. type: slave
  50. file: "/var/cache/bind/db.dn42-lab.de"
  51. masters:
  52. - 172.22.149.225 port 5353
  53. - zone: byeob.de.
  54. type: slave
  55. file: "/var/cache/bind/db.byeob.de"
  56. masters:
  57. - 172.22.149.225 port 5353
  58. - zone: p2p-node.de.
  59. type: slave
  60. file: "/var/cache/bind/db.p2p-node.de"
  61. masters:
  62. - 172.22.149.225 port 5353
  63. - zone: p2p-router.de.
  64. type: slave
  65. file: "/var/cache/bind/db.p2p-router.de"
  66. masters:
  67. - 172.22.149.225 port 5353
  68. - zone: i2phides.me.
  69. type: slave
  70. file: "/var/cache/bind/db.i2phides.me"
  71. masters:
  72. - 172.22.149.225 port 5353
  73. - zone: crxn.de.
  74. type: slave
  75. file: "/var/cache/bind/db.crxn.de"
  76. masters:
  77. - 172.22.149.225 port 5353
  78. ## dn42
  79. - zone: bandura.dn42.
  80. type: slave
  81. file: "/var/cache/bind/db.bandura.dn42"
  82. masters:
  83. - 172.22.149.225 port 5353
  84. - zone: 224/27.149.22.172.in-addr.arpa.
  85. type: slave
  86. file: "/var/cache/bind/db.172.22.149.224_27"
  87. masters:
  88. - 172.22.149.225 port 5353
  89. - zone: 112/28.149.22.172.in-addr.arpa.
  90. type: slave
  91. file: "/var/cache/bind/db.172.22.149.112_28"
  92. masters:
  93. - 172.22.149.225 port 5353
  94. - zone: 1.3.c.f.e.4.3.2.4.0.d.f.ip6.arpa.
  95. type: slave
  96. file: "/var/cache/bind/db.fd04:234e:fc31::_48"
  97. masters:
  98. - 172.22.149.225 port 5353
  99. ## NeoNetwork
  100. - zone: bandura.neo.
  101. type: slave
  102. file: "/var/cache/bind/db.bandura.neo"
  103. masters:
  104. - 172.22.149.225 port 5353
  105. - zone: 149.127.10.in-addr.arpa.
  106. type: slave
  107. file: "/var/cache/bind/db.10.127.149.224_27"
  108. masters:
  109. - 172.22.149.225 port 5353
  110. - zone: 1.3.c.f.7.2.1.0.0.1.d.f.ip6.arpa.
  111. type: slave
  112. file: "/var/cache/bind/db.fd10:127:fc31::_48"
  113. masters:
  114. - 172.22.149.225 port 5353
  115. ## CRXN
  116. - zone: bandura.crxn.
  117. type: slave
  118. file: "/var/cache/bind/db.bandura.crxn"
  119. masters:
  120. - 172.22.149.225 port 5353
  121. - zone: docs.crxn.
  122. type: slave
  123. file: "/var/cache/bind/db.docs.crxn"
  124. masters:
  125. - 172.22.149.225 port 5353
  126. - zone: 2.b.2.0.6.b.8.5.2.9.d.f.ip6.arpa.
  127. type: slave
  128. file: "/var/cache/bind/db.fd92:58b6:2b2::_48"
  129. masters:
  130. - 172.22.149.225 port 5353
  131. - zone: 6.6.6.2.7.3.e.3.c.5.d.f.ip6.arpa.
  132. type: slave
  133. file: "/var/cache/bind/fd5c:3e37:2666::_48"
  134. masters:
  135. - 172.22.149.225 port 5353
  136. # myip.dn42
  137. - zone: myip.dn42.
  138. type: slave
  139. file: "/var/cache/bind/db.myip.dn42"
  140. masters:
  141. - 172.22.149.225 port 5353
  142. - zone: 81/32.0.20.172.in-addr.arpa.
  143. type: slave
  144. file: "/var/cache/bind/db.172.20.0.81_32"
  145. masters:
  146. - 172.22.149.225 port 5353
  147. - zone: 1.8.0.0.2.4.d.0.2.4.d.0.2.4.d.f.ip6.arpa.
  148. type: slave
  149. file: "/var/cache/bind/db.fd42:d42:d42:81::_64"
  150. masters:
  151. - 172.22.149.225 port 5353
  152. # CRXN root
  153. - zone: crxn.
  154. type: slave
  155. file: "/var/cache/bind/db.crxn-root"
  156. masters:
  157. - 172.22.149.225 port 5353
  158. # dn42 root
  159. - zone: dn42.
  160. type: stub
  161. masters:
  162. - fd42:180:3de0:30::1 port 53
  163. - fd42:180:3de0:10:5054:ff:fe87:ea39 port 53
  164. - zone: 20.172.in-addr.arpa.
  165. type: stub
  166. masters:
  167. - fd42:180:3de0:30::1 port 53
  168. - fd42:180:3de0:10:5054:ff:fe87:ea39 port 53
  169. - zone: 21.172.in-addr.arpa.
  170. type: stub
  171. masters:
  172. - fd42:180:3de0:30::1 port 53
  173. - fd42:180:3de0:10:5054:ff:fe87:ea39 port 53
  174. - zone: 22.172.in-addr.arpa.
  175. type: stub
  176. masters:
  177. - fd42:180:3de0:30::1 port 53
  178. - fd42:180:3de0:10:5054:ff:fe87:ea39 port 53
  179. - zone: 23.172.in-addr.arpa.
  180. type: stub
  181. masters:
  182. - fd42:180:3de0:30::1 port 53
  183. - fd42:180:3de0:10:5054:ff:fe87:ea39 port 53
  184. - zone: 10.in-addr.arpa.
  185. type: stub
  186. masters:
  187. - fd42:180:3de0:30::1 port 53
  188. - fd42:180:3de0:10:5054:ff:fe87:ea39 port 53
  189. - zone: d.f.ip6.arpa.
  190. type: stub
  191. masters:
  192. - fd42:180:3de0:30::1 port 53
  193. - fd42:180:3de0:10:5054:ff:fe87:ea39 port 53
  194. # Freifunk zones
  195. - zone: ff3l.
  196. type: stub
  197. masters:
  198. - 10.119.0.5 port 53
  199. - 10.119.0.4 port 53
  200. - 10.119.0.10 port 53
  201. - fdc7:3c9d:b889:a272::5 port 53
  202. - fdc7:3c9d:b889:a272::4 port 53
  203. - fdc7:3c9d:b889:a272::a port 53
  204. - zone: fffd.
  205. type: stub
  206. masters:
  207. - 10.185.0.1 port 53
  208. - 10.185.0.2 port 53
  209. - 10.185.0.4 port 53
  210. - fd00:65a8:93a4::1 port 53
  211. - fd00:65a8:93a4::2 port 53
  212. - fd00:65a8:93a4::4 port 53
  213. - zone: fftr.
  214. type: stub
  215. masters:
  216. - 10.172.0.14 port 53
  217. - 10.172.0.16 port 53
  218. - 2001:bf7:fc0f::14 port 53
  219. - 2001:bf7:fc0f::16 port 53
  220. - zone: ffhl.
  221. type: stub
  222. masters:
  223. - fdef:ffc0:3dd7::801 port 53
  224. - fdef:ffc0:3dd7::a01 port 53
  225. - fdef:ffc0:3dd7::c01 port 53
  226. - fdef:ffc0:3dd7::e01 port 53
  227. - 10.130.0.252 port 53
  228. - 10.130.0.253 port 53
  229. - 10.130.0.254 port 53
  230. - 10.130.0.255 port 53
  231. # Hack root
  232. - zone: hack.
  233. type: slave
  234. file: "/var/cache/bind/db.hack-root"
  235. masters:
  236. - 172.22.149.225 port 5353
  237. - zone: 31.172.in-addr.arpa.
  238. type: slave
  239. file: "/var/cache/bind/db.172.31.0.0_16"
  240. masters:
  241. - 172.22.149.225 port 5353
  242. - zone: 100.10.in-addr.arpa.
  243. type: slave
  244. file: "/var/cache/bind/db.10.100.0.0_16"
  245. masters:
  246. - 172.22.149.225 port 5353
  247. - zone: 101.10.in-addr.arpa.
  248. type: slave
  249. file: "/var/cache/bind/db.10.101.0.0_16"
  250. masters:
  251. - 172.22.149.225 port 5353
  252. - zone: 102.10.in-addr.arpa.
  253. type: slave
  254. file: "/var/cache/bind/db.10.102.0.0_16"
  255. masters:
  256. - 172.22.149.225 port 5353
  257. - zone: 103.10.in-addr.arpa.
  258. type: slave
  259. file: "/var/cache/bind/db.10.103.0.0_16"
  260. masters:
  261. - 172.22.149.225 port 5353
  262. # NeoNetwork root
  263. - zone: neo.
  264. type: slave
  265. file: "/var/cache/bind/db.neo-root"
  266. masters:
  267. - 172.22.149.225 port 5353
  268. - zone: 127.10.in-addr.arpa.
  269. type: slave
  270. file: "/var/cache/bind/db.10.127.0.0_16"
  271. masters:
  272. - 172.22.149.225 port 5353
  273. - zone: 7.2.1.0.0.1.d.f.ip6.arpa.
  274. type: slave
  275. file: "/var/cache/bind/db.fd10.127_32"
  276. masters:
  277. - 172.22.149.225 port 5353