From 7bb49844ae94847041258d0cdb34be9cf61b9da9 Mon Sep 17 00:00:00 2001 From: "stephane.david" Date: Sat, 11 Jul 2026 11:37:50 +0200 Subject: [PATCH] Corrected network acl --- docker-compose.yml | 21 +++++++++------------ 1 file changed, 9 insertions(+), 12 deletions(-) diff --git a/docker-compose.yml b/docker-compose.yml index a67f949..d36da00 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -1,10 +1,10 @@ services: dns-server: container_name: dns-server - hostname: dns-server + hostname: dns-server2 image: docker.io/technitium/dns-server:latest # For DHCP deployments, use "host" network mode and remove all the port mappings, including the ports array by commenting them - # network_mode: "host" + network_mode: "host" ports: - "5380:5380/tcp" #DNS web console (HTTP) # - "53443:53443/tcp" #DNS web console (HTTPS) @@ -18,7 +18,7 @@ services: # - "8053:8053/tcp" #DNS-over-HTTP service (use with reverse proxy) # - "67:67/udp" #DHCP service environment: - - DNS_SERVER_DOMAIN=dns-server #The primary domain name used by this DNS Server to identify itself. + - DNS_SERVER_DOMAIN=dns-server2.maison #The primary domain name used by this DNS Server to identify itself. - DNS_SERVER_ADMIN_PASSWORD=St&ph@ne10Nove.@1976 #DNS web console admin user password. # - DNS_SERVER_ADMIN_PASSWORD_FILE=password.txt #The path to a file that contains a plain text password for the DNS web console admin user. # - DNS_SERVER_PREFER_IPV6=false #DNS Server will use IPv6 for querying whenever possible with this option enabled. @@ -37,7 +37,7 @@ services: # - DNS_SERVER_RECURSION_ALLOWED_NETWORKS=127.0.0.1, 192.168.1.0/24 #Comma separated list of IP addresses or network addresses to allow recursion. Valid only for `UseSpecifiedNetworkACL` recursion option. This option is obsolete and DNS_SERVER_RECURSION_NETWORK_ACL should be used instead. - DNS_SERVER_ENABLE_BLOCKING=true #Sets the DNS server to block domain names using Blocked Zone and Block List Zone. # - DNS_SERVER_ALLOW_TXT_BLOCKING_REPORT=false #Specifies if the DNS Server should respond with TXT records containing a blocked domain report for TXT type requests. - # - DNS_SERVER_BLOCK_LIST_URLS= #A comma separated list of block list URLs. + - DNS_SERVER_BLOCK_LIST_URLS=https://raw.githubusercontent.com/StevenBlack/hosts/master/alternates/gambling/hosts,https://dl.red.flag.domains/adguard/red.flag.domains.txt #A comma separated list of block list URLs. # - DNS_SERVER_FORWARDERS=1.1.1.1, 8.8.8.8 #Comma separated list of forwarder addresses. # - DNS_SERVER_FORWARDER_PROTOCOL=Tcp #Forwarder protocol options: Udp, Tcp, Tls, Https, HttpsJson. - DNS_SERVER_LOG_USING_LOCAL_TIME=true #Enable this option to use local time instead of UTC for logging. @@ -45,13 +45,10 @@ services: - DNS_SERVER_LOG_MAX_LOG_FILE_DAYS=365 #Max number of days to keep the log files. Log files older than the specified number of days will be deleted automatically. Set 0 to disable auto delete. # - DNS_SERVER_STATS_ENABLE_IN_MEMORY_STATS=false #This option will enable in-memory stats and only Last Hour data will be available on Dashboard. No stats data will be stored on disk. - DNS_SERVER_STATS_MAX_STAT_FILE_DAYS=365 #Max number of days to keep the dashboard stats. Stat files older than the specified number of days will be deleted automatically. Set 0 to disable auto delete. + - TZ=Europe/Paris volumes: - - config:/etc/dns - - logs:/var/log/technitium/dns + - /var/lib/docker/volumes/technitium/config:/etc/dns + - /var/lib/docker/volumes/technitium/logs:/var/log/technitium/dns restart: unless-stopped - sysctls: - - net.ipv4.ip_local_port_range=1024 65535 #remove when using "host" network mode - -volumes: - config: - logs: \ No newline at end of file + # sysctls: + # - net.ipv4.ip_local_port_range=1024 65535 #remove when using "host" network mode