PowerDNS Recursor Helm Chart with global transparency mode, seeking for feedback

Vitali Quiering via Pdns-users <[email protected]> Wed, 1 Apr 2026 14:08:52 +0200
Newsgroups gmane.network.dns.powerdns.user
Message-ID <[email protected]>
--===============5946985570062875846==
Content-Type: multipart/alternative;
	boundary="Apple-Mail=_85E468BF-03A3-42B1-8F16-952B903B6066"


--Apple-Mail=_85E468BF-03A3-42B1-8F16-952B903B6066
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Hi list,

in our company we are using AWS EKS with the default CoreDNS setup that =
they provide.
Recently we have deployed the node-local-dns helm chart to avoid issue =
with AWS=E2=80=99 usage policies. For certain cases, we are an ESP and =
send a lot of emails, I developed a helm chart for PowerDNS Recursor =
because I couldn=E2=80=99t find any back in the day.

This chart has now evolved to a replacement of the node-local-dns =
daemonset. If deployed in transparency mode it will update iptables and =
add IPs to the listener config to allow transparent takeover of all DNS =
traffic throughout the cluster. Additionally you can still use a service =
IP to spread traffic over all pods.

The helm chart: =
https://artifacthub.io/packages/helm/klicktipp/powerdns-recursor, =
https://github.com/klicktipp/helm-charts/tree/main/charts/powerdns-recurso=
r
The init and sidecar image: =
https://github.com/klicktipp/containers/tree/main/images/pdns-transparent-=
dns

I would love to get some feedback on this, even if it=E2=80=99s bad. :-D

Cheers,
Vitali=

--Apple-Mail=_85E468BF-03A3-42B1-8F16-952B903B6066
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html aria-label=3D"message body"><head><meta http-equiv=3D"content-type" =
content=3D"text/html; charset=3Dutf-8"></head><body =
style=3D"overflow-wrap: break-word; -webkit-nbsp-mode: space; =
line-break: after-white-space;">Hi list,<div><br></div><div>in our =
company we are using AWS EKS with the default CoreDNS setup that they =
provide.</div><div>Recently we have deployed the node-local-dns helm =
chart to avoid issue with AWS=E2=80=99 usage policies. For certain =
cases, we are an ESP and send a lot of emails, I developed a helm chart =
for PowerDNS Recursor because I couldn=E2=80=99t find any back in the =
day.</div><div><br></div><div>This chart has now evolved to a =
replacement of the node-local-dns daemonset. If deployed in transparency =
mode it will update iptables and add IPs to the listener config to allow =
transparent takeover of all DNS traffic throughout the cluster. =
Additionally you can still use a service IP to spread traffic over all =
pods.</div><div><br></div><div>The helm chart:&nbsp;<a =
href=3D"https://artifacthub.io/packages/helm/klicktipp/powerdns-recursor">=
https://artifacthub.io/packages/helm/klicktipp/powerdns-recursor</a>,&nbsp=
;<a =
href=3D"https://github.com/klicktipp/helm-charts/tree/main/charts/powerdns=
-recursor">https://github.com/klicktipp/helm-charts/tree/main/charts/power=
dns-recursor</a></div><div>The init and sidecar image:&nbsp;<a =
href=3D"https://github.com/klicktipp/containers/tree/main/images/pdns-tran=
sparent-dns">https://github.com/klicktipp/containers/tree/main/images/pdns=
-transparent-dns</a></div><div><br></div><div>I would love to get some =
feedback on this, even if it=E2=80=99s bad. =
:-D</div><div><br></div><div>Cheers,</div><div>Vitali</div></body></html>=

--Apple-Mail=_85E468BF-03A3-42B1-8F16-952B903B6066--

--===============5946985570062875846==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Pdns-users mailing list
[email protected]
https://mailman.powerdns.com/mailman/listinfo/pdns-users

--===============5946985570062875846==--