might want to check https://github.com/alexandru/social-publish
HN user
rdme
actually that is exactly how i am currently running it - dogfooding from my Mac
sudo numa install handles launchd, numa then becomes tailscale's fallback resolver
docker socket service discovery - on the roadmap
honestly, nothing major, just deployed the docker-compose to a hetzner $5 instance https://github.com/razvandimescu/numa/tree/main/packaging/re...
then submit a pr to Frank https://github.com/DNSCrypt/dnscrypt-resolvers/blob/master/v...
sovereign naming without ICANN or registrars - pkarr through DHT (not blockchain)
no, you are actually telling the relay where to redirect your question from the start (because you are encrypting the question with the public key of the destination resolver) - the relay sending the question where it wants would result in the destination to not be able to decrypt it
The relay sees IP + ciphertext, the target sees question + relay's IP. No single party gets both
I agree with you, however that's a separate problem that needs to be solved
They solve different things. ODoH hides your question, not who you're talking to.
The relay is a systemd unit on a VPS, Caddy for TLS, SSRF-hardened (regex-strict hostnames, no IP literals). eTLD+1 same-operator check rejects relay+target run by the same org by default. HPKE is odoh-rs from Cloudflare
``` cargo install numa
# set mode = "odoh" in numa.toml ```
this must be some a/b testing as i’m not seeing anything different
actually it does have a dismissable banner i haven’t even noticed
How would this work? One would connect it's repository to a cloud platform that would then act based on the existing daemons of the repo?
Just shipped numa v0.13.0: added request hedging (fires a parallel query after 10ms if the primary stalls, inspired by Google's Tail at Scale paper) wire-level cache with serve-stale (RFC 8767) and a DoT client for encrypted upstream.
Wrote about the tail latency investigation: https://numa.rs/blog/posts/fixing-doh-tail-latency.html
should be fixed by #54 in 0.10.3 thanks again!
Thanks for pointing this out! I’ve created https://github.com/razvandimescu/numa/issues/36
let me know how it goes
Split DNS already works — Numa auto-detects Tailscale forwarding rules from the system config. Queries matching .<ts.net> go to Tailscale’s DNS, everything else goes through Numa
If you want to skip Tailscale entirely for home servers, Numa’s LAN discovery auto-finds machines running Numa on the same network. Or add static records in numa.toml for machines that don’t run it.
This was started as a learning project, went from the start to the lowest level then I've just added features I wanted one by one, it just made the most sense
let me know if you do it!
Numa can do recursive resolution from root nameservers + DNSSEC, .numa local domains with auto HTTPS for dev, and LAN service discovery. What features would you be interested in?
It definitely is and you can see it in the git commits. The DNS wire protocol parser was the original learning project I wrote to understand the spec. Later features (recursive resolver, DNSSEC validation, the dashboard) were built with the help of AI
exactly, I'll add a pr soon that tells the os (and browsers) that is'a a valid domain
also in romanian nume = name(dns) and I also get the easter egg of that well known Romanian song numa numa :) https://www.youtube.com/watch?v=YnopHCL1Jk8
On OpenWRT — it's musl-based Linux so the binary should run the arm one would need a crosscompile Free BSD can be done (pr's welcome?)
Yes — numa install generates a local CA and stores it in the system trust store. When you register a .numa service, it generates a per-service TLS cert signed by that CA
With 390K blocked domains: ~31MB total process footprint. Breakdown: - Blocklist: 23.4MB (390K domains) - Cache: 3.8MB (4.4K entries) - Query log, SRTT, runtime: ~4MB
It binds to 0.0.0.0:53 by default, so just point your devices' DNS to the board's IP
Multiple blocklists already work -https://github.com/razvandimescu/numa/blob/main/numa.toml#L4... The pieces are already there for libnuma, it could be done, would you share what use case you have in mind?
I hit reply on the wrong post and you can't delete comments or at least I don't see how it can be done
because I clicked reply on the wrong one and you can't delete it...
Is it possible you didn't start it as root ( sudo numa install)? Does dig {mygivenname}.numa @127.0.0.1 return 127.0.0.1 ? What OS are you on? Maybe you report it as an issue?
Actually, if you point a container's DNS at the host (dns: [host.docker.internal] in compose), it works for resolution + ad blocking for the reverse however, I've added it on the radar, thanks!
Yes sir! The query log is at GET /querylog (or on the dashboard) shows every request with domain, type, path (forwarded/recursive/cached/blocked) and latency