- unbound: add loopback DoH listener (127.0.0.1@8080, http-notls-downstream); interface-automatic-ports lists 8080 so interface-automatic does not silently drop the non-53 listener; access-control driven by resolver_allowed_netblocks - caddy: add RedHat/COPR install path, caddy_template var, /var/log/caddy dir; new Caddyfile-resolver.j2 terminates LE TLS and h2c-proxies to unbound, enforcing the client allow-list via remote_ip - resolvers: open 80/443 in firewall; prefer post-quantum SSH key exchange (sntrup761x25519-sha512) via validated sshd_config.d drop-in - bind9: zone.j2 emits AAAA records; add ipv6 for resolver1/2 (2606:1c80::240/250) - playbook: run caddy role on the resolvers group |
||
|---|---|---|
| .. | ||
| plans | ||