Seriously though, Knot's DNSSEC signing with automatic ZSK rollover is the only way I'd run DNSSEC on more than two zones. Doing this manually with OpenDNSSEC + BIND was brittle. NSD + OpenDNSSEC was worse.
Late to this but: has anyone mentioned that Contabo's 256MB VPS is KVM now, not OpenVZ? The RAM is actually dedicated. My NSD instance has been stable for 14 months on their Singapore DC.
Still wouldn't run without secondaries. But the "256MB is fake" era is mostly over.
Confirmed. I have one in St. Louis. However the disk is still network-backed and can stall under load. I/O wait, not RAM, is what kills my NSD reloads when I push a big zone update.
Mi servidor, mi problema. I run NSD on 256MB Contabo Mexico City. Well, Nuremberg, because Contabo has no Mexico DC. The latency to CDMX is 150ms. For my use case—personal mail, three domains—this is fine.
If I had customers I would pay for anycast. For myself, I accept the tradeoff.
declarative or death
Post a reply
You need an account to reply.
Log in or
register to join the conversation.