Skip to Content.
Sympa Menu

discuss - [opennic-discuss] Food for thought?

discuss AT lists.opennicproject.org

Subject: Discuss mailing list

List archive

Chronological Thread  
  • From: Rouben <rouben AT rouben.net>
  • To: discuss AT lists.opennicproject.org
  • Subject: [opennic-discuss] Food for thought?
  • Date: Tue, 14 Jul 2026 18:27:35 -0400

Hi all,

The recent email thread quoted below about a server “disappearing” from the server list triggered a lightbulb moment in my mind… I sincerely don’t mean to criticize and hope to start a friendly and respectful discussion.

I thought that it might be helpful to share the core infrastructure code with a centralized git repository that all members could review. I feel like this might be helpful towards addressing a few core issues that I’ve always felt persisted at OpenNIC:

1. The infrastructure code to track servers, for example, seems to be an “opaque box” to most people. It’d be nice to know how the service(s) are set up and maintained and what makes them tick, for both educational but also peer-review purposes.
2. There doesn’t seem to be any continuity / succession planning at all for some of the infrastructure: if the maintainer(s) go away for whatever reason, the infrastructure just disappears / goes dark and likely would have to be adopted by a vounteer and set up from scratch. Having the infrastructure documented can help with this, rather than having to reinvent the wheel from scratch.
3. Almost all server operator(s) are on their own when it comes to:
3.a. Deployment playbooks / configurations and hardening, including updates to hardening (e.g. firewall rules). Sure there is some very bare bones and somewhat dated stuff on the Wiki, but that’s just sufficient… it could be a lot more comprehensive.
3.b. Threat information sharing … for example, information regarding attack specifics, mitigation techniques or their post-mortems.
3.c. Infrastructure monitoring beyond external pings recorded by the server list page.
4. At a higher level, it’d be nice to have semi-formal change management practices that are a balance of democratic voting and technical reasoning. I think we have this largely, although variables like dependencies and impact are discussed ad hoc as part of the democratic voting/discussion process. Aside from mailing list history there seem to be no other records.

For git we can use something self-hosted like gitlab (overkill IMO), gitea or its European fork, forgejo. The latter is used by Berlin-based Codeberg.

For documentation, we could just stick to best practices with an expectation that all server operators abide by them at a minimum. I don’t think actual enforcement is necessary, although conducting more comprehensive scans of server deployments to verify that certain best practices are in place (like querying for the latest known zone record change and checking if the servers are compliant with their responses vs. just doing a basic check that the server is “up”).

Threat sharing and incident response is the trickiest, since we would likely need a synchronous communication medium. Something like Signal or Matrix (if self-hosted is preferable) could work.

Rouben

On Tue, Jul 14, 2026 at 13:11 Jeff Taylor <shdwdrgn AT sourpuss.net> wrote:
I think the record was lost, I don't see this entry in the current
list.  Unfortunately this is a problem we've been seeing and haven't
found the source of the trouble yet.  could you add your server again
and let me know when that's been done?  I'm also on the IRC chat if you
want to reach out directly.


On 7/13/26 09:37, N C wrote:
> Hello OpenNIC community,
>
> I'd like to announce my new public Tier 2 DNS server:
>
>    IPv4: 142.196.173.2
>    IPv6: 2603:9001:f01:ad99::1002
>    Software: Unbound 1.25.1
>    Features: UDP/TCP port 53
>    Logging: Queries not logged
>    Location: United States
>
> The server uses OpenNIC root hints (ns2/ns4/ns6/ns8.opennic.glue)
> and has been tested to resolve both ICANN and OpenNIC TLDs.
>
> I've registered the server at servers.opennic.org. Please let me
> know if any adjustments are needed.
>
> Thanks,
> Nicholas Carlton
>
>
> --------
> You are a member of the OpenNIC Discuss list.
> You may unsubscribe by emailing discuss-unsubscribe AT lists.opennicproject.org



--------
You are a member of the OpenNIC Discuss list.
You may unsubscribe by emailing discuss-unsubscribe AT lists.opennicproject.org



Archive powered by MHonArc 2.6.24.

Top of Page