2020-12-13 13:59:44 +00:00
|
|
|
server:
|
|
|
|
# provided by pkg_apt:unbound-anchor
|
|
|
|
auto-trust-anchor-file: "/var/lib/unbound/root.key"
|
|
|
|
|
|
|
|
verbosity: 0
|
|
|
|
|
2021-04-24 10:00:09 +00:00
|
|
|
statistics-interval: 60
|
2021-04-24 09:45:58 +00:00
|
|
|
extended-statistics: yes
|
2020-12-13 13:59:44 +00:00
|
|
|
statistics-cumulative: no
|
|
|
|
|
|
|
|
num-threads: ${threads}
|
|
|
|
|
2021-06-03 11:59:15 +00:00
|
|
|
% if node.has_bundle('nftables') and not node.has_bundle('vmhost'):
|
|
|
|
# Use nftables to manage access to this service
|
2020-12-13 13:59:44 +00:00
|
|
|
interface: 0.0.0.0
|
|
|
|
interface: ::0
|
|
|
|
access-control: 0.0.0.0/0 allow
|
|
|
|
access-control: ::/0 allow
|
|
|
|
% else:
|
|
|
|
interface: 127.0.0.1
|
|
|
|
interface: ::1
|
|
|
|
access-control: 127.0.0.1 allow
|
|
|
|
access-control: ::1 allow
|
|
|
|
% endif
|
|
|
|
|
2020-12-22 08:22:37 +00:00
|
|
|
msg-cache-size: ${cache_size}
|
|
|
|
msg-cache-slabs: ${cache_slabs}
|
|
|
|
rrset-cache-size: ${cache_size}
|
|
|
|
rrset-cache-slabs: ${cache_slabs}
|
2020-12-13 13:59:44 +00:00
|
|
|
cache-max-ttl: ${max_ttl}
|
2020-12-22 08:22:37 +00:00
|
|
|
cache-max-negative-ttl: 600
|
2020-12-13 13:59:44 +00:00
|
|
|
|
2020-12-22 08:24:10 +00:00
|
|
|
prefetch: yes
|
|
|
|
prefetch-key: yes
|
|
|
|
|
2020-12-13 13:59:44 +00:00
|
|
|
use-syslog: yes
|
|
|
|
log-queries: no
|
|
|
|
|
|
|
|
root-hints: "/etc/unbound/root-hints.txt"
|
|
|
|
|
|
|
|
tls-cert-bundle: "/etc/ssl/certs/ca-certificates.crt"
|
|
|
|
|
|
|
|
remote-control:
|
2021-06-05 11:28:25 +00:00
|
|
|
% if node.has_bundle('telegraf'):
|
2020-12-13 13:59:44 +00:00
|
|
|
control-enable: yes
|
|
|
|
% else:
|
|
|
|
control-enable: no
|
|
|
|
% endif
|