Giving back: authoritative DNS and clear private boundaries
October 3, 2026
DNS has followed me from ISP networking into platform and SRE work. It is easy to treat it as background plumbing until a service name resolves to the wrong place or a private record becomes visible where it should not.
The PowerDNS authoritative lab focuses on records you own. An authoritative server answers for its configured zones. It is a different responsibility from recursively finding answers on behalf of clients, which I cover in the recursor post.
Make the answers visible
This example uses two authoritative instances with BIND zone files to demonstrate internal and external answers. The demo runs on loopback ports and uses example names; it is not a public delegation or a complete production DNS service.
Compare the intended answers directly. A name meant for the internal side should appear there; a private-only name should not appear in the external demonstration. Check record types, zone serials, and negative answers as well as the obvious successful lookup.
These BIND-backed instances are not an implementation of PowerDNS native views. The official views documentation describes that separate, experimental feature and its backend requirements. I want the repository's actual design to be clear, rather than borrowing a feature name that the example does not use.
Bootstrap and steady state are different
Basic DNS has to work before a local delivery platform can depend on it. Later, you can put the intended zone configuration in your chosen GitHub or GitLab repositories and deliver reviewed changes with that platform's native runner.
Editing zone files includes maintaining SOA serials and checking the resulting answers. The BIND backend used here does not turn the API into a general zone-editing interface. Read the repository's update workflow before expecting an API operation to persist a change.
The reader benefit is a small, inspectable model of ownership and exposure. That model helps with internal services, cloud networking, and the supporting infrastructure around an AI platform. The series guide puts DNS in its place in the bootstrap sequence.