6 ms·
This is not really a great idea. It's just adding more brittleness to your system. Leave DNS to people with distributed DNS networks and redundancy. I mean obv
by ebbv 9y ago
This is not really a great idea. It's just adding more brittleness to your system. Leave DNS to people with distributed DNS networks and redundancy.
I mean obviously you can do it if you want to, I'm not stopping you, but to me it's silly.
- zzzcpan 9y agoDNS is only distributed if you run it yourself, not when you rely on a centralized service.
- zrail 9y agoThat's... that's not what "distributed" means. DNS is distributed because it's arranged as a tree, with the root nodes delegating to the TLDs delegating to individual name servers for each zone. Just because someone chooses to use a service instead of running a nameserver themselves doesn't make DNS centralized.
- sp332 9y agoI pretty sure that's not what eebv meant. They're talking about redundancy for high-availability.
- zzzcpan 9y agoRedundancy and high-availability is something DNS has by design. DNS providers are incentivized to highlight those things as if they were unique to them, but actually the only thing they can offer is anycast for lower latency. Incidentally anycast also makes them less reliable, not more.
- zzzcpan 9y agoIf a bunch of people choose a single DNS provider they all create a centralized point in this tree, through witch all of the clients wanting to access their services have to go through. This is exactly what centralization is and is exactly what caused downtime for a lot of websites when Dyn was DDoSed.
- toast0 9y agoDNS is designed for adversity. Assuming you don't care much about how long it takes to resolve, most recursive resolvers will try pretty hard to resolve your names -- all the authoritative severs will be tried, so you just need to make sure one is working. I use free secondaries for my personal domains (now using he.net), which helps a lot.
- petee 9y agoAll you need to do is have atleast 2 physically separate servers and DNS by design does the distributed/redundancy part - as long as the records are setup correctly, any resolver will find you, and public ones like Google DNS will cache the result for most people.
- SpaethCo 9y agoAlong these lines, one of the obvious things missed in this post: monitoring. Setting up DNS servers on low cost VPS providers has some inherenet risks as they tend to attract all kinds of abuse, which can lead to things like mass scale UDP filtering to keep operations online. When I scaled down my colo footprint I started to move DNS operations to various VPS providers to maintain redundancy, but kept my monitoring in place to perform health checks at 60 second intervals. Finally got annoyed enough with all of the filtering events tripping monitoring that I migrated everything to a hosted DNS provider.