ZSoftly
Talk to our team

Whitepaper · 10 pages · September 2026

Authoritative DNS with PowerDNS

Primary and secondary nameservers across two sites, deployed and patched with Ansible

A reference design for authoritative DNS on PowerDNS with dnsdist in front. It covers API-driven zone management, signed zone transfers to a secondary with its own local data, cache and delegation practice, and one-site-at-a-time patching. It also lists the eight alerts we keep and six anonymised production lessons.

  • PowerDNS
  • dnsdist
  • DNSSEC
  • Ansible
  • Monitoring
Sites
2
Primary and secondary, separate upstreams
Alerts
8
The signals we keep on every node
Lessons
6
From our own postmortems
Checks
12
Readiness checklist before any cutover

Inside

What the paper covers

  • Reference Architecture

    dnsdist in front of PowerDNS, primary and secondary with TSIG transfers

  • API-First Zone Management

    One write path, serial bumps on every change, NOTIFY to the secondary

  • Caches and Deletion

    Why you purge both cache layers together and give deletes their own playbook

  • Delegation and DNSSEC

    Host objects and glue at the registry, validation before any DS record

  • Patching and CVE Response

    Security polling alerts, both products patched, one site at a time

  • Lessons from Production

    Stale REFUSED answers, cross-site latency and zones with no SOA

Steps

The migration, step by step

  1. 01Assess zones and delegationStep 1
  2. 02Design sites and write pathStep 2
  3. 03Build roles and alertsStep 3
  4. 04Pilot a low-risk zoneStep 4
  5. 05Cut over in batchesStep 5

Get the full paper

10 pages, PDF, 1.0 MB. Your first hour with our engineers is free.