Self-hosting overview
Everything that runs Bancuh DNS is open source, and packaged so you can run the same thing on your own server with Docker Compose.
Reasons to run your own:
- Your own rules. Choose your own blocklists, allow what the public filter blocks, or turn off SafeSearch.
- Closer and faster. Put a server on your home network or in a nearby data centre.
- Your own privacy. Only you hold the logs.
- Capacity. Serve a school or office without shared per-IP limits.
How it fits together
Section titled “How it fits together”Each Bancuh DNS server runs two containers:
+-----------------------------+ +----------------------+clients --> | dnsdist-acme | ---> | bancuh-dns | ---> internet | :53 plain DNS | | :1153 plain DNS | | :853 DNS-over-TLS | | blocklist filtering | | :443 DNS-over-HTTPS | | daily list updates | | :80 Let's Encrypt | | recursive resolver | | :8080 query logs (HTTP) | | (or forwarders) | | :8443 query logs (HTTPS) | +----------------------+ | rate limiting | +-----------------------------+| Component | What it does | Repository |
|---|---|---|
| adblock-dns-server | The Docker Compose setup and the blocklist configuration used by the public service. Start here. | ragibkl/adblock-dns-server |
| bancuh-dns | The filtering DNS server, written in Rust. Compiles the blocklist, answers or blocks lookups, and resolves everything else with a built-in recursive resolver (Unbound). | ragibkl/bancuh-dns |
| dnsdist-acme | The front end, built on dnsdist. Handles DoT and DoH with automatic Let’s Encrypt certificates, rate limiting and the query logs page. | ragibkl/dnsdist-acme |
Images are published for amd64, arm64, 386 and arm/v7, so a Raspberry
Pi with enough memory works as well as a cloud server.
What you’ll need
Section titled “What you’ll need”- A Linux machine, such as a VPS, a home server, a virtual machine or a Raspberry Pi. A current Ubuntu Server LTS is a good default.
- About 2 GiB of RAM. The default blocklist has millions of entries.
- Docker with the Compose plugin.
- Port 53 free on the machine.
- For DoT and DoH: a public IP address, a domain name pointing at it, and ports 80, 443 and 853 reachable from the internet.
Run with Docker ComposeGet a server answering lookups in a few minutes.
Enable DoT & DoHAdd encrypted DNS with automatic certificates.
Customise the blocklistAdd your own sources, allowlists and rewrites.
Configuration referenceEvery environment variable, for both containers.