Architecture
This guide covers the essentials. Read the full upstream guide on GitHub → For a specific release, select its tag in the repository.
BoronDNS separates zone acquisition from query serving. It obtains data from configured primaries, validates transfers, and publishes complete generations for UDP and TCP query workers.
From primary to answer
- Static configuration or catalog membership establishes transfer plans.
- SOA polling and authorized NOTIFY trigger AXFR or IXFR refresh work.
- Transferred data is validated and prepared as a query image or incremental overlay.
- Last-good state is committed to disk before the new generation becomes visible.
- Query workers answer from the published in-memory generation.
Readers retain a consistent zone entry while answering, so a query cannot observe a partially installed generation. A failed refresh retains the previous valid data until it expires.
Durable state
Checkpoints and bounded incremental journals support restart continuity. Restore validates checksums and zone contents; missing, corrupt, incompatible, or expired state cannot replace an initial transfer. The cache does not replace primary backups.
Service boundaries
DNS listeners handle queries and NOTIFY. Transfer source addresses control outbound connections. Separate management listeners expose health, metrics, and optional observability endpoints.
BoronDNS has no recursive resolver or primary-serving mode. BoronGun and BoronGen are separate test tools. See protocol support for further scope limits.
Implementation details
The upstream architecture guide covers storage, concurrency, trust boundaries, and the source map. For sizing and tuning, use capacity limits and the query storage and packet I/O reference.