Skip to content
DNS Conduit
Unreleased
Initializing search
egon1024/DNSConduit
DNS Conduit
egon1024/DNSConduit
Home
Getting started
Getting started
Overview
What Conduit is for
Install and run
Minimal configuration
First query
Concepts
Concepts
Overview
Architecture and packet path
Runtime and concurrency
Policy & routing
Policy & routing
Overview
Client ACLs
Rules and actions
Data sources
Pools and backends
Backend health
Retries and transactions
Control plane
Control plane
Overview
Configuration model
Overlay merge strategy
Config file
Reload and export
gRPC and conduitctl
Rhai
Rhai
Overview
Host API
Host API
Overview
Transaction (txn)
Runtime
Lookups
Metrics
Script logging
For rules
For rules
Overview
Hooks and phases
Sandbox limits
Observability
Observability
Overview
Metrics
Metrics configurability
Built-in metric registry
Built-in metrics
Tracing
Event export
Logging
Performance
Performance
Overview
Tuning evidence (studies)
Tuning evidence (studies)
Overview
Runtime — Sync vs split_io
Runtime — Ingress concurrency (sync)
Runtime — I/O vs ingress (split_io)
Runtime — Split_io bulk topology
Runtime — Cache hit vs forward
Runtime — Memory vs LMDB warm cache_hit
Runtime — Memory vs LMDB high-churn cache
Observability — Metrics scrape tax
Observability — Metrics collect vs emit
Observability — OTLP tax under load
Observability — Metrics scrape (split_io)
Observability — Aggressive scrape cadence
Observability — Dnstap emit tax
Observability — Combined metrics + dnstap
Observability — Logging verbosity tax
Observability — Pipeline tracing tax
Lifecycle — Drain policy under slow
Methodology
Reproduce against a binary
Reference results
Scenarios
Guides
Guides
Overview
Backend health
DNS answer cache
Dual-stack forwarding
Rule action order
Declarative failover
Rhai policy
Control plane workflows
Metrics and tracing
Operator metrics bases
Metrics beyond bases
Event export and dnstap
OTLP metrics push smoke
Dataplane runtime tuning
Security
Security
Overview
API keys
mTLS
Troubleshooting
Interop
Interop
Overview
Conduit behavior
Cases
Cases
auth-dangling-cname-nxdomain
auth-unknown-zone-refused
basic-a-forward
cache-forward-a
cache-lmdb-durability-restart-hit
cache-miss-then-hit-a
cache-nxdomain-miss-then-hit
cache-rotate-rrset
dataplane-split-io-forward
dnsmasq-cname-ignored-nonlocal
dnsmasq-local-cname-expand
edns-opt-passthrough-smoke
fixture-auth-a
fixture-auth-aaaa
fixture-auth-api-a
fixture-auth-cname-a
fixture-auth-nodata-mx
fixture-auth-nxdomain
forward-parity-smoke
health-drain-avoids-backend
health-drain-resume-returns
health-fail-open-all-down
health-live-dead-prefer-live
health-passive-fast-trip
passthrough-aa-auth-a
pdns-recursor-rd0-refused
peer-tc-passthrough
recursive-outside-aa-shape
rhai-soft-drop
rules-clear-drop
rules-drop-now
rules-qname-forward
rules-soft-drop
stub-aaaa-for-a-only
unbound-local-cname-no-chase
By publisher
By publisher
CZ.NIC
ISC
NLnet Labs
PowerDNS
thekelleys
Glossary
Release notes
Release notes
Overview
Unreleased
Reference
Reference
Overview
Config schema
Config schema
Overview
Listeners
Acls
Rules
Rhai
Data sources
Lookup
Caches
Pools
Health
Forward
Orchestrator
Dataplane
Shutdown
Control
Logging
Metrics and tracing
Events
gRPC and CLI
Versions
Contributing
License
Unreleased
No unreleased operator-facing changes.