Bug 238893 - dns/unbound: Add profile support to rc script
Summary: dns/unbound: Add profile support to rc script
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Some People
Assignee: Kubilay Kocak
Keywords: feature
Depends on: 240163
  Show dependency treegraph
Reported: 2019-06-30 09:35 UTC by C
Modified: 2019-09-03 09:32 UTC (History)
1 user (show)

See Also:
bugzilla: maintainer-feedback? (jaap)

Patch to test out (5.06 KB, patch)
2019-08-12 10:24 UTC, Jaap Akkerhuis
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description C 2019-06-30 09:35:28 UTC
There are multiple use-cases that requires running multiple unbound instances.

- if you want to have an instance with DNS64 enabled but also need an instance without DNS64

- if you want to have different ACLs per interface

- if you need to run unbound in two distinct routing contexts (setfib)

There are multiple examples of ports having multi-instance support:

- https://lists.freebsd.org/pipermail/freebsd-hackers/2013-June/043013.html
- security/tor https://svnweb.freebsd.org/ports/head/security/tor/files/tor.in?revision=463489&view=markup

It were great if the unbound port rc.d script gets native support for multiple instances.

Each intances should have its own config file and optionally support distinct user and distinct fib.
Comment 1 Jaap Akkerhuis 2019-07-01 13:46:09 UTC
Someone else asked me (privately) about this some time ago. He/She promised me to propose a patch but that never happened, so I guess it is time to roll my own. I'm rather busy on the moment but I'll see what I can in the coming days.

Since dns/nsd has a similar startup structure as unbound, I will base it on the nsd rc script.

Comment 2 Jaap Akkerhuis 2019-08-12 10:24:40 UTC
Created attachment 206472 [details]
Patch to test out

I whipped up this version. Do test it and report results. Thanks!
Comment 3 Jaap Akkerhuis 2019-09-03 08:10:34 UTC
This got added to release 1.9.3 of unbound (See PR #240163) so I we can close this one