acme-dns historically assumed a single authoritative DNS server.
In environments using DNS master/slave (secondary) servers with zone transfers,
this can result in inconsistent responses, missing records, or SERVFAILs
during DNS challenge validation.
This PR adds proper support for DNS slave configurations by:
bumping SOA serial when zone data changes
sending DNS NOTIFY to slaves
supporting AXFR zone transfers
Changes
implement SOA serial bump logic
add DNS NOTIFY handling
support AXFR for slave servers
refactor DNS engine for slave compatibility
Testing
Tested in environments with:
master + one or more DNS slaves
zone transfer (AXFR) working
TXT protocols resolving correctly from both master and slaves
No regressions observed on single-server setups.
Checklist
Works with DNS slaves
No breaking changes
Follow project conventions
Tests updated
CI passes
### Motivation
acme-dns historically assumed a single authoritative DNS server.
In environments using DNS master/slave (secondary) servers with zone transfers,
this can result in inconsistent responses, missing records, or SERVFAILs
during DNS challenge validation.
This PR adds proper support for DNS slave configurations by:
- bumping SOA serial when zone data changes
- sending DNS NOTIFY to slaves
- supporting AXFR zone transfers
### Changes
- implement SOA serial bump logic
- add DNS NOTIFY handling
- support AXFR for slave servers
- refactor DNS engine for slave compatibility
### Testing
Tested in environments with:
- master + one or more DNS slaves
- zone transfer (AXFR) working
- TXT protocols resolving correctly from both master and slaves
No regressions observed on single-server setups.
### Checklist
- [x] Works with DNS slaves
- [x] No breaking changes
- [x] Follow project conventions
- [x] Tests updated
- [x] CI passes
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Motivation
acme-dns historically assumed a single authoritative DNS server.
In environments using DNS master/slave (secondary) servers with zone transfers,
this can result in inconsistent responses, missing records, or SERVFAILs
during DNS challenge validation.
This PR adds proper support for DNS slave configurations by:
Changes
Testing
Tested in environments with:
No regressions observed on single-server setups.
Checklist
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.