v2.0.0-rc10
Gerstep/cybosv2.0.0-rc10Dec 22, 2025by qdm12
AI Summary
A release candidate refining DNS internals, connection pooling, and defining Go API changes for future stability.
Key Highlights
- Implemented connection pooling for DNS over TLS to reduce stress on TCP-connections-rate-limiting
- Defined Go API breaking changes for the nameserver package
- Added HEALTH_SERVER_ADDRESS option for healthcheck configuration
- Enhanced logging for blocked elements and NXDOMAIN responses
Breaking Changes
- pkg/nameserver.GetDNSServers now returns []netip.Addr instead of []netip.AddrPort
- pkg/nameserver.GetDNSServers now returns an error
- internal/local: 'site' and 'network' TLDs are now classified as public
New Features
- HEALTH_SERVER_ADDRESS configuration option
- REBINDING_PROTECTION_EXEMPT_HOSTNAMES option
- Filter middleware logging improvements
Full Release Notes
## Features - DNS over TLS now uses a pool of connections to re-use TCP connections when possible (#150) - `HEALTH_SERVER_ADDRESS` option, defaulting to `127.0.0.1:9999` - by default log i/o timeout errors are logged at debug level because these are fairly common - `REBINDING_PROTECTION_EXEMPT_HOSTNAMES` option - `pkg/middlewares/filter`: log blocked elements with a reason ## Fixes - `internal/local`: "site" and "network" TLDs are public, not local - `pkg/middlewares/localdns`: - do not log request twice on errors - do not debug log NXDOMAIN coded responses since these happen often especially with search domains - `internal/support/ipv6`: handle Windows error message - Grafana dashboard plain DNS section updated ## Go API breaking changes - `pkg/nameserver`: `GetDNSServers` - does not return localhost IPs if no nameserver is found - returns an eventual error - returns []netip.Addr instead of []netip.AddrPort since it can only be an ip address without port ## Maintenance - Grafana JSON dashboard upgraded to newer schema version 3 - Fix documentation URLs and CI links check - bump markdownlint from v11 to v21