#rfc2136
Currently the DNS (bind9) server has records from 3 sources

1. True Static IPs, I have very few of these left, managed by terraform via RFC2136
2. Kubernetes services/ingress/gateway records. Updated by external-dns via RFC2136
3. DHCP addresses. This includes true dynamic and reserved records […]
Original post on transitory.social
transitory.social
June 5, 2025 at 10:48 PM
Die API die dafür vorgesehen ist heißt RFC2136...
June 12, 2026 at 8:12 AM
Der Certbot benutzt den rfc2136-Mechanismus für die Zertifikat-Erneuerung.
June 12, 2026 at 8:01 AM
Home Lab status :
✅ KVM provisioning with ansible and cloud-init
✅ K3s setup in HA
✅ kube-vip for controller
✅ Flux
✅ kube-vip for servicelb
✅ Mozilla SOPS
✅ Discord notifications
✅ longhorn
✅ traefik
✅ external DNS GCP + rfc2136
🚧 cert manager
September 18, 2023 at 3:50 PM
Äh... Ich mach das mit >100 Domains. Update der Zonen per Script, certbot und RFC2136 Interface.
June 12, 2026 at 7:39 AM
📰 You can run a DNS server (2025)

💬 Exec: Own DNS+RFC2136 for ACME (duh); acme.sh/Unix & simple-acme/Win; PowerDNS. Vibe: pragmatic. Positive 😊

https://news.ycombinator.com/item?id=47453738
March 25, 2026 at 5:45 AM
Ha, funktioniert: LoadBalancer für #dovecot wird automatisch erzeugt, automatisch in DNS eingetragen und automatisch ein TLS-Zertifikat erzeugt. Langsam nimmt mein Mail-auf-Kubernetes-Setup Form an.

#k8s #externaldns #certmanager #rfc2136
August 4, 2024 at 12:13 PM
I wrote a small service to update one or more domains on your DNS server with your current public IP through a TSIG-signed dynamic zone update. Essentially a DIY DynDNS.

github.com/dbrgn/ddns-m...

Written in #Rust, repo already includes #Nix package and module.
GitHub - dbrgn/ddns-my-public-ip: Send a TSIG-signed dynamic zone update (RFC2136) to a DNS server, which updates certain records with your public IP.
Send a TSIG-signed dynamic zone update (RFC2136) to a DNS server, which updates certain records with your public IP. - dbrgn/ddns-my-public-ip
github.com
January 24, 2025 at 10:46 PM
This and most ACME bot implementations support DNS-01 with a lot (almost all?) of DNS API providers, which make also things much easier in my experience.

I even got this working with k3s/Traefik/custom Knot DNS server using standard RFC2136 DNS UPDATE

Route53 is guaranteed to be supported.
February 1, 2026 at 7:54 PM
I am also playing around with my RaspberryPI5-RKE2-Cluster. I use LongHorn for storage (500GB NVME via PCIe-hat) and everything runs fine - except CertManager DNS01/RFC2136 LetsEncrypt WildcardDomain. But MetalLB and Traefik do run very fine. My Domain is a deep-subdomain (3 segments). nice hobby :)
February 28, 2025 at 3:12 AM
queria tirar um cochilo mas to aqui passando calor e brigando com RFC2136
September 26, 2024 at 8:38 PM
The options for DNS are a bit more tricky.

Ideally I'd stick with something supported by cert-manager dns-challenge that also won't get expensive when slammed.

I guess a service that supports RFC2136, or PowerDNS API would also be viable
GitHub - zachomedia/cert-manager-webhook-pdns: A PowerDNS webhook for cert-manager
A PowerDNS webhook for cert-manager. Contribute to zachomedia/cert-manager-webhook-pdns development by creating an account on GitHub.
github.com
June 5, 2025 at 12:51 AM
It's always DNS...shout-out to HE.net not only for their free IPv6-tunnels but also their free DNS-slaves and detailed instructions that you should really read carefully!

#dns #ipv6 #rfc2136
July 15, 2024 at 10:06 AM
certbot-dns-rfc2136 4.2.0-1 any RFC2136 DNS Authenticator plugin for Certbot

#Extra-Testing #any

Origin | Interest | Match
Arch Linux - certbot-dns-rfc2136 4.2.0-1 (any)
archlinux.org
August 9, 2025 at 10:03 AM
basicamente um erro num if que devia ser case insensitive mas não é, fazendo o plugin escolher o tipo de algorítmo default que era md5. o fix já foi commitado mas obviamente ainda não tá incluída na minha dist (ubuntu 24.04)
Capitalization inconsistency in rfc 2136 algorithm detection · Issue #10177 · certbot/certbot
Using certbot-rfc2136. In dns_rfc2136.py I see: if not self.ALGORITHMS.get(algorithm.upper()): raise errors.PluginError("Unknown algorithm: {0}.".format(algorithm)) so having dns_rfc2136_algorithm ...
github.com
August 28, 2025 at 1:08 PM
LHS Episode #601: Automated Certificates Deep Dive

Hello and welcome to Episode 601 of Linux in the Ham Shack. In this episode, the hosts discuss the RFC2136 for remote, authenticated DNS updates and how it can be...

73 de The LHS Crew

lhs.fyi/601

#hamr #hamradio #lhspodcast #linux #opensource
December 7, 2025 at 10:58 PM