Files
coredns/man/coredns-https.7
Ben Kochie 311a9915da Improve RFC links (#8612)
The `tools.ietf.org` site now redirects to `www.rfc-editor.org`.
* Update various URLs to the new site.
* Make links to `www.rfc-editor.org` consistent.

Signed-off-by: SuperQ <superq@gmail.com>
2026-10-08 10:21:06 +02:00

73 lines
1.6 KiB
Groff

.\" Generated by Mmark Markdown Processer - mmark.miek.nl
.TH "COREDNS-HTTPS" 7 "October 2026" "CoreDNS" "CoreDNS Plugins"
.SH "NAME"
.PP
\fIhttps\fP - configures DNS-over-HTTPS (DoH) server options.
.SH "DESCRIPTION"
.PP
The \fIhttps\fP plugin allows you to configure parameters for the DNS-over-HTTPS (DoH) server to fine-tune the security posture and performance of the server.
.PP
This plugin can only be used once per HTTPS listener block.
.SH "SYNTAX"
.PP
.RS
.nf
https {
max\_connections NON\_NEGATIVE\_INTEGER
max\_streams NON\_NEGATIVE\_INTEGER
}
.fi
.RE
.IP \(bu 4
\fB\fCmax_connections\fR limits the number of concurrent TCP connections to the HTTPS server. The default value is 200 if not specified. Set to 0 for unbounded.
.IP \(bu 4
\fB\fCmax_streams\fR limits the number of concurrent HTTP/2 streams per HTTPS connection. This helps prevent unbounded streams on a single connection, exhausting server resources. The default value is 250 if not specified. Set to 0 to use the underlying HTTP/2 transport default.
.SH "EXAMPLES"
.PP
Set custom limits for maximum connections and streams:
.PP
.RS
.nf
https://.:443 {
tls cert.pem key.pem
https {
max\_connections 100
max\_streams 100
}
whoami
}
.fi
.RE
.PP
Set both values to 0 to disable the CoreDNS limits (unbounded connections and the underlying HTTP/2 transport stream default), matching CoreDNS behaviour before v1.14.0:
.PP
.RS
.nf
https://.:443 {
tls cert.pem key.pem
https {
max\_connections 0
max\_streams 0
}
whoami
}
.fi
.RE