Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / CoreDNS

Live

DCA Hardened DNS Server for CoreDNS — Support & Quick Start

A hardened, CVE-patched virtual machine image running CoreDNS — the Cloud Native Computing Foundation's flexible, plugin-based DNS server — on Oracle Linux 9.

At a glance

StatusLive on Oracle Cloud Marketplace
Version1.14.6
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 53/tcp, 53/udp
CategoryNetworking
Upstream licenceApache-2.0
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@<public-ip>
  2. CoreDNS runs as a systemd service, as the unprivileged coredns user (holding only CAP_NET_BIND_SERVICE), serving DNS on port 53 (TCP and UDP) on all interfaces as a caching forwarding resolver. Its health (8080) and readiness (8181) endpoints answer on 127.0.0.1 only. Check status:
    sudo systemctl status coredns
  3. Smoke-test from the instance (dig ships in bind-utils:
    sudo dnf -y install bind-utils if it is not present):
    curl -s http://127.0.0.1:8080/health
    curl -s http://127.0.0.1:8181/ready
    dig @127.0.0.1 example.com

    From a client your security list permits:

    dig @<public-ip> example.com

  4. To serve your own zones, put a zone file (with its SOA and NS records) in /etc/coredns and add a server block to /etc/coredns/Corefile, for example:
    example.internal:53 {
    file /etc/coredns/db.example.internal
    }

    The reload plugin applies the change automatically within about 45 seconds (sudo journalctl -u coredns shows "Reloading complete"); to apply it immediately:

    sudo systemctl restart coredns

  5. Port 53 (TCP and UDP) is already permitted in the host firewall and is the only port reachable from outside the instance; 8080 and 8181 stay on loopback and blocked. Restrict 53 in your VCN security list to your clients' CIDR. Never expose an open resolver to the internet: it will be abused for amplification attacks.
  6. Configuration and zone files live in /etc/coredns (the Corefile plus your zone files); the service's working directory is /var/lib/coredns. Upstream forwarders come from /etc/resolv.conf (the VCN resolver). Recommended sizing: at least 2 OCPU (4 vCPU) and 16 GB memory; scale OCPU with query volume.

The image is CVE-patched at build time. Apply ongoing OS updates with:

sudo dnf -y update

CoreDNS itself is a static binary in /usr/local/bin (not a package); CoreDNS fixes ship as new image versions.

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

CoreDNS is a trademark of The Linux Foundation. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the CoreDNS project, the CNCF, or The Linux Foundation.