Release notes — 0.14.0
Released 2026-06-23 with DNS Conduit 0.14.0.
New features
- Operator documentation — published manual at https://egon1024.github.io/DNSConduit/ covering getting started, architecture, policy and routing, control plane, Rhai scripting, observability, guides, reference, glossary, and troubleshooting. Versioned snapshots deploy with each release tag.
- Release notes — per-version operator release notes on the docs site; contributors stage bullets in this file before each release. See Release notes.
- Release artifacts — GitHub Releases can ship Linux
amd64tarballs, Debian packages,SHA256SUMS, and an SPDX SBOM. See Install and run. - Apache 2.0 license — project licensed under Apache 2.0 with DCO sign-off for contributions.
- Declarative rules — expanded selectors and actions, including ordered action lists,
set_sourceon request rules, andset_retry_sourcefor retry egress. See Rules and actions. - Rhai scripting — broader transaction and DNS wire API (including IANA class/type/rcode enums), user-defined metrics from scripts, lookup-table support, and compile-time validation of scripts on config reload. See Rhai and Host API overview.
- Metrics profiles —
metrics.profile: minimal(default-style volume counters) vsfull(richer labels, phase timing, and Linux process gauges). See Built-in metrics and Operator metrics bases. - OpenTelemetry metrics export — OTLP push for built-in metrics when
metrics.otelis configured. See Metrics. - Event export — improved dnstap and structured event filtering, selectors, and extra-field handling. See Event export.
- Control plane overlay —
conduitctl applymerges patches into the accumulated overlay by default;--replaceand--clearremain available. Patches that include file-only sections (rules,metrics,tracing) are rejected at apply time. See Configuration model and Reload and export. - Sample keys — optional
sample_keyon listeners and rules for trace and event sampling. See Tracing.
Improvements
- Quieter default logging — per-query log lines are at
debug; defaultinfoemphasizes lifecycle and control-plane events. See Logging. - Retry behavior — clearer same-pool retry semantics and transaction limits. See Retries and transactions.
- Config paths — relative paths for TLS material and other file references resolve from the config file directory.
conduitctl validatechecks path resolution. - Logging format — removed ASCII control-character rendering from log output.
- Development tracer — dnstap decode utility renamed to
conduit-dnstap-tracer.
Upgrade notes
- Review Minimal configuration if you rely on implicit defaults — the control plane and metrics export remain opt-in; a sparse config still needs only
schema_version,listeners, andpools. - After upgrading, validate YAML with
conduitctl validate --file …and reload or restart as usual. Rhai syntax errors in scripts now fail reload instead of being deferred to query time. - If you depend on verbose per-query process logs at
info, raiselogging.leveltodebugor use metrics and event export for traffic visibility.
All changes in this release (automated pull request list).