Whitepaper · 10 pages · September 2026

# Authoritative DNS with PowerDNS

Primary and secondary nameservers across two sites, deployed and patched with Ansible

[Download the PDF 1.0 MB](https://zcp.zsoftly.ca/downloads/whitepapers/powerdns-authoritative-dns.pdf)

[Talk to an engineer](https://calendar.app.google/ceY8b2bxhCYgB1ot9)

[![Cover of the Running Authoritative DNS with PowerDNS and dnsdist whitepaper](https://zcp.zsoftly.ca/images/whitepapers/powerdns-authoritative-dns-cover.webp) Free download, no form](https://zcp.zsoftly.ca/downloads/whitepapers/powerdns-authoritative-dns.pdf)

A reference design for authoritative DNS on PowerDNS with dnsdist in front. It covers API-driven zone management, signed zone transfers to a secondary with its own local data, cache and delegation practice, and one-site-at-a-time patching. It also lists the eight alerts we keep and six anonymised production lessons.

- PowerDNS
- dnsdist
- DNSSEC
- Ansible
- Monitoring

Sites

2

Primary and secondary, separate upstreams

Alerts

8

The signals we keep on every node

Lessons

6

From our own postmortems

Checks

12

Readiness checklist before any cutover

Inside

## What the paper covers

- ### Reference Architecture

  dnsdist in front of PowerDNS, primary and secondary with TSIG transfers
- ### API-First Zone Management

  One write path, serial bumps on every change, NOTIFY to the secondary
- ### Caches and Deletion

  Why you purge both cache layers together and give deletes their own playbook
- ### Delegation and DNSSEC

  Host objects and glue at the registry, validation before any DS record
- ### Patching and CVE Response

  Security polling alerts, both products patched, one site at a time
- ### Lessons from Production

  Stale REFUSED answers, cross-site latency and zones with no SOA

Steps

## The migration, step by step

1. 01

   Assess zones and delegation

   Step 1
2. 02

   Design sites and write path

   Step 2
3. 03

   Build roles and alerts

   Step 3
4. 04

   Pilot a low-risk zone

   Step 4
5. 05

   Cut over in batches

   Step 5

## Get the full paper

10 pages, PDF, 1.0 MB. Your first hour with our engineers is free.

[Download the PDF](https://zcp.zsoftly.ca/downloads/whitepapers/powerdns-authoritative-dns.pdf)

[Book a discovery call](https://calendar.app.google/ceY8b2bxhCYgB1ot9)

## More whitepapers

[See every whitepaper](https://zcp.zsoftly.ca/resources/whitepapers/)

- [Compute and Storage, Priced Separately 10 pages · October 2026](https://zcp.zsoftly.ca/resources/whitepapers/compute-storage-priced-separately/)
- [Object Storage by Industry 10 pages · September 2026](https://zcp.zsoftly.ca/resources/whitepapers/object-storage-by-industry/)
- [Building and Operating a Private Cloud on Apache CloudStack and Ceph 10 pages · September 2026](https://zcp.zsoftly.ca/resources/whitepapers/cloudstack-ceph-private-cloud/)
- [Configuration Management at Platform Scale with Ansible 10 pages · September 2026](https://zcp.zsoftly.ca/resources/whitepapers/ansible-configuration-management/)
- [Enterprise EKS Auto Mode Migration Roadmap 10 pages · September 2026](https://zcp.zsoftly.ca/resources/whitepapers/eks-migration-guide/)
- [CI/CD Pipelines for Infrastructure as Code 10 pages · September 2026](https://zcp.zsoftly.ca/resources/whitepapers/cicd-iac-guide/)
