3.4 KiB
3.4 KiB
Changelog
All notable changes to nxdns are recorded here. The format follows Keep a Changelog, and the project uses Semantic Versioning.
Sections are written by hand. Nothing here is generated from commit messages: the point of the file is to say what changed for an operator, which a commit subject rarely does.
[Unreleased]
[0.0.1] - 2026-08-07
First release. Everything below is new.
Added
- Forwarding DNS server. UDP and TCP listeners with a wire-format parser and
encoder written against RFC 1035 and EDNS(0), a bounded worker model, per-client
rate limiting and a
pausecontrol that stops filtering without stopping resolution. - Encrypted upstreams. DNS-over-HTTPS and DNS-over-TLS clients over a pool that tracks per-upstream health and fails over, with SNI and certificate verification driven by a per-upstream TLS name.
- DoH and DoT endpoints. nxdns also answers as an encrypted resolver, with a certificate store that reloads on disk changes and through the API, so renewals do not need a restart.
- Blocklist filtering. Subscriptions in hosts, plain-domain and Adblock-Plus-style formats, compiled into a compact matcher; per-group allow and block rules with wildcards; safe-search enforcement.
- Per-client policy groups. Clients are identified by address and assigned to groups, so the filtering a device gets depends on which device it is.
- Local DNS. Local A/AAAA/CNAME/PTR records and conditional forwarding of internal zones to another resolver.
- Cache. A bounded in-memory cache that respects upstream TTLs and expires entries rather than serving them stale.
- Query log. Queries land in SQLite under a retention policy in both rows and days, with disk-full self-protection that degrades instead of corrupting, and a live SSE stream of the same events.
- Web UI and REST API. A React single-page admin UI embedded in the binary,
a REST API with a served OpenAPI document, session authentication, API rate
limiting and Prometheus-style
/metrics. - Configuration. A ZON configuration file seeds the database on first boot;
after that the database is the truth, and
nxdns export/nxdns importmove configuration in and out.nxdns checkvalidates a file without starting. - CLI.
run,check,export,import,versionandhelp. - Packaging. A hardened systemd unit with a sysusers fragment, and a
FROM scratchcontainer image holding the binary, a CA bundle and the licence files, assembled by a builder stage pinned toalpine:3.22by digest. Nothing from Alpine ships in the published image except that CA bundle. - Releases. Tags publish five assets — static musl tarballs for
x86_64-linux-muslandaarch64-linux-musl,IMAGE-DIGEST.txtnaming the multi-architecture container image by digest,SHA256SUMS.txtover those three, andSHA256SUMS.txt.asc, a detached signature over the checksum file.zig build distandzig build verify-distproduce and check the same artifacts on a laptop. - Licensing. EUPL-1.2, with a
THIRD-PARTY-NOTICESfile in every tarball and image assembled from a reviewed inventory of what the artifacts contain. - Documentation. A Diátaxis split — tutorial, how-to, reference, explanation — with drift guards that fail the build when the reference pages fall behind the code.