mirror of
https://github.com/coredns/coredns.git
synced 2026-10-09 03:55:21 -04:00
The `tools.ietf.org` site now redirects to `www.rfc-editor.org`. * Update various URLs to the new site. * Make links to `www.rfc-editor.org` consistent. Signed-off-by: SuperQ <superq@gmail.com>
137 lines
3.6 KiB
Groff
137 lines
3.6 KiB
Groff
.\" Generated by Mmark Markdown Processer - mmark.miek.nl
|
|
.TH "COREDNS-SECONDARY" 7 "October 2026" "CoreDNS" "CoreDNS Plugins"
|
|
|
|
.SH "NAME"
|
|
.PP
|
|
\fIsecondary\fP - enables serving a zone retrieved from a primary server.
|
|
|
|
.SH "DESCRIPTION"
|
|
.PP
|
|
With \fIsecondary\fP you can transfer (via AXFR) a zone from another server. The retrieved zone is
|
|
\fInot committed\fP to disk (a violation of the RFC). This means restarting CoreDNS will cause it to
|
|
retrieve all secondary zones.
|
|
|
|
.PP
|
|
If the primary server(s) don't respond when CoreDNS is starting up, the AXFR will be retried
|
|
indefinitely every 10s.
|
|
|
|
.SH "SYNTAX"
|
|
.PP
|
|
.RS
|
|
|
|
.nf
|
|
secondary [ZONES...]
|
|
|
|
.fi
|
|
.RE
|
|
|
|
.IP \(bu 4
|
|
\fBZONES\fP zones it should be authoritative for. If empty, the zones from the configuration block
|
|
are used. Note that without a remote address to \fIget\fP the zone from, the above is not that useful.
|
|
|
|
|
|
.PP
|
|
A working syntax would be:
|
|
|
|
.PP
|
|
.RS
|
|
|
|
.nf
|
|
secondary [zones...] {
|
|
transfer from ADDRESS [ADDRESS...]
|
|
catalog [MEMBER\-ZONES...]
|
|
fallthrough [ZONES...]
|
|
}
|
|
|
|
.fi
|
|
.RE
|
|
|
|
.IP \(bu 4
|
|
\fB\fCtransfer from\fR specifies from which \fBADDRESS\fP to fetch the zone. It can be specified multiple
|
|
times; if one does not work, another will be tried. Transferring this zone outwards again can be
|
|
done by enabling the \fItransfer\fP plugin.
|
|
.IP \(bu 4
|
|
\fB\fCcatalog\fR treats the transferred zone as an RFC 9432 catalog zone. After each successful catalog
|
|
transfer, CoreDNS adds and removes the catalog member zones and transfers those member zones from
|
|
the same primary servers. Optional \fBMEMBER-ZONES\fP restrict which member zone names are accepted;
|
|
each name also matches its subdomains. With no \fBMEMBER-ZONES\fP, all member zones are accepted for
|
|
backward compatibility. RFC 9432 Section 7 recommends configuring this restriction because a
|
|
catalog producer otherwise controls which zones the consumer serves. A member in another catalog
|
|
remains a name clash unless the current catalog's \fB\fCcoo\fR property points to the newly updated
|
|
catalog. During that ownership migration, CoreDNS preserves the current zone data only when both
|
|
catalogs use the same member node label.
|
|
.IP \(bu 4
|
|
\fB\fCfallthrough\fR If a query for a record in the zone results in NXDOMAIN, the query will be passed
|
|
to the next plugin in the chain. If \fB[ZONES...]\fP are listed, then only queries for those zones
|
|
will be subject to fallthrough. This can be useful in split DNS setups where the secondary zone
|
|
contains only partial records.
|
|
|
|
|
|
.PP
|
|
When a zone is due to be refreshed (refresh timer fires) a random jitter of 5 seconds is applied,
|
|
before fetching. In the case of retry this will be 2 seconds. If there are any errors during the
|
|
transfer in, the transfer fails; this will be logged.
|
|
|
|
.SH "EXAMPLES"
|
|
.PP
|
|
Transfer \fB\fCexample.org\fR from 10.0.1.1, and if that fails try 10.1.2.1.
|
|
|
|
.PP
|
|
.RS
|
|
|
|
.nf
|
|
example.org {
|
|
secondary {
|
|
transfer from 10.0.1.1 10.1.2.1
|
|
}
|
|
}
|
|
|
|
.fi
|
|
.RE
|
|
|
|
.PP
|
|
Or re-export the retrieved zone to other secondaries.
|
|
|
|
.PP
|
|
.RS
|
|
|
|
.nf
|
|
example.net {
|
|
secondary {
|
|
transfer from 10.1.2.1
|
|
}
|
|
transfer {
|
|
to *
|
|
}
|
|
}
|
|
|
|
.fi
|
|
.RE
|
|
|
|
.PP
|
|
Restrict a catalog consumer to member zones at or below \fB\fCexample.org\fR and \fB\fCinternal.example\fR.
|
|
|
|
.PP
|
|
.RS
|
|
|
|
.nf
|
|
catalog.example {
|
|
secondary {
|
|
transfer from 10.1.2.1
|
|
catalog example.org internal.example
|
|
}
|
|
}
|
|
|
|
.fi
|
|
.RE
|
|
|
|
.SH "BUGS"
|
|
.PP
|
|
Only AXFR is supported and the retrieved zone is not committed to disk.
|
|
|
|
.SH "SEE ALSO"
|
|
.PP
|
|
See the \fItransfer\fP plugin to enable zone transfers \fIto\fP other servers.
|
|
RFC 5936 details the AXFR protocol, and RFC 9432 defines DNS catalog zones.
|
|
|