Technitium DNS server

Technitium DNS can be deployed as a container or as a package on a linux OS. Both of which are used at EOD.

Install

Raspberry Pi / Technitium Marketplace VM

  1. The technitium project has a provided shell script to automate the installation process

    Raspberri Pi only

    This step is only applicable to Raspberri Pi install, marketplace images come with technitium preinstalled.

    curl -sSL https://download.technitium.com/dns/install.sh | sudo bash   
    
  2. Deploy certbot to pull certificates using Let's Encrypt

    Use public certificate authority

    Using trusted signing authorities instead of self-signed certificates will make the installation process easier and more reliable.

    sudo apt install certbot python3-certbot-dns-cloudflare
    

    Create the secret for cloudflare DNS-01 integration

    sudo mkdir -p /root/.secrets/certbot
    
    cat <<EOF | sudo tee /root/.secrets/certbot/cloudflare.ini
    dns_cloudflare_api_token = <my_cloudflare_api_key>
    EOF
    

    Technitium requires a p12 certificate. Generate strong random password

    sudo mkdir -p /root/.secrets/technitium
    
    openssl rand -base64 74 | tr -d '=+/' | cut -c1-64 | tee /root/.secrets/technitium/pfx-password
    
    Create a deploy hook for certbot to encode LE certificate as a pfx

    cat <<EOF | tee /etc/letsencrypt/renewal-hooks/deploy# cat technitium-pfx
    #!/bin/sh
    set -eu
    
    DOMAIN="dns-server-pi.technitium-cluster.endofday.com"
    DEST="/etc/dns/certs/dns-server.pfx"
    PASSWORD_FILE="/root/.secrets/technitium/pfx-password"
    
    install -d -m 700 "$(dirname "$DEST")"
    
    openssl pkcs12 -export \
      -out "${DEST}.new" \
      -inkey "/etc/letsencrypt/live/${DOMAIN}/privkey.pem" \
      -in "/etc/letsencrypt/live/${DOMAIN}/fullchain.pem" \
      -passout "file:${PASSWORD_FILE}"
    
    chmod 600 "${DEST}.new"
    chown dns-server:dns-server "${DEST}.new"
    mv -f "${DEST}.new" "${DEST}"
    EOF
    

    Request certificate from LE

    sudo certbot certonly --dns-cloudflare --dns-cloudflare-credentials /root/.secrets/certbot/cloudflare.ini -d radius01.endofday.com
    

Kubernetes

TODO: generate kube doc