Skip to content

DNS host for 500 zones—anycast on budget possible?

VPS Hosting by lookuppierre 4 replies 276 views
#1

I have 500 zones to serve, mostly static. The Contabo anycast is how to say... not offered. They do not have the product. So I build.

Three VPS: KnownHost Amsterdam, RackNerd Amsterdam, OVHcloud London. €3 each, « budget ». Running PowerDNS with native replication. BGP sessions to... no BGP. I use « anycast » by announcing same IP across three regions via different providers. The hack, she is not elegant.

Latency from EU to Singapore: 300ms. Not 'orrible for DNS, but not good. I need real anycast, real BGP. My research says I need ASN, /24, $$$$. The « impossible » for hobby.

Anyone doing production DNS on $3 VPS? I found one blog claiming 99.99% on this setup. I do not believe. Oui, I am cynical.

Current status: replication breaks monthly. I fix by hand. Scales poorly.

How to say... help?

prix fixe infrastructure: €5/mo
#2
lookuppierre said:
Real anycast, real BGP

Pro tip: you don't need ASN for basic anycast. Oracle Cloud free tier has anycast DNS as managed service. But since you want DIY:

1. Get ASN from RIPE (costs ~€50/year) or use private ASN with providers who allow it
2. Rent /24 from HostHatch or buy on IRC market (sketchy, heads up)
3. Announce via BGP to two upstreams minimum
4. Run Bird or FRR on each VPS

Actually cheaper path: use GreenCloudVPS's BGP session product. $5/month includes one /48 IPv6 and BGP feed. IPv6 anycast works same, costs fraction.

I've run this on Oracle free tier ARM for two years. Same ASN, three regions, native anycast. Not production-grade but close.

Heads up: most $3 VPS providers filter BGP. Verify before you buy.

licensing is a suggestion
#3
olya said:
Use private ASN

Why private ASN? Get real one, the server will thank you. So, I run VPS with BGP for three years, production resolver, 10k queries/second. I tell you:

  • ASN from RIPE: 50 euro
  • /24 from forum: 200 euro one time
  • VPS from three providers: 9 dollar monthly
  • Sleep: zero,

The hijacking fear? What fear. I announce /24 only, no upstream accept longer. So, secure enough. Do it or don't, but stop the « research » and build.

My setup: Bird2, health checks, automatic withdraw if resolver dies. 99.97% real uptime. Incha'allah not needed, I engineer proper.

256 cores for a blog. why not?
#4

Wesh lookuppierre

Le server DNS حلو if you know how to manage. I run anycast on five VPS, mix of KnownHost and local provider in Casablanca. French-arabic network, best network.

The « BGP hijacking »: incha'allah your peers filter RPKI. If not, problem. But problem for everyone, not you only. I see hijack monthly on RIPE stats, never me. Coincidence ? Maybe. Good filters ? Also maybe.

My config uses Bird with BFD. Fast failover, 300ms detection. Replication: PowerDNS with native, same as you. I fix by hand also, but less: once per three month. Acceptable for price.

Space before punctuation is law .

RAID 1: because paranoia pays
#5

PowerDNS with 500 zones: 200MB if you cache aggressive. My home lab: 128GB DDR4, runs circles around your $9 setup. Humblebrag, sure, but relevant.

The real bottleneck isn't RAM. It's the anycast convergence time. Your $3 VPS has how many cores? One. Bird runs, PowerDNS runs, health checks run. CPU steal from neighbors, BGP update delayed, route withdrawn slow. 30 seconds of blackhole.

I tried similar on Time4VPS 1GB. Swapped to 2GB, problems vanished. Not RAM pressure—kernel scheduler happier with headroom.

Budget anycast works. I've seen it. But how much RAM is "enough" varies by provider oversubscription. Your OVHcloud Singapore is probably 10:1 contended. Test with iperf, not hope. I used https://bench.sh for that.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft