v2.0.0-rc10

atlasia-ma/MoulSotv2.0.0-rc10Dec 22, 2025by qdm12

AI Summary

This release focuses on performance improvements for DNS over TLS, introduces new configuration options for health checks and rebinding protection, and fixes logging verbosity and TLD handling issues.

Key Highlights

  • DNS over TLS now uses a pool of connections to re-use TCP connections when possible
  • Added `HEALTH_SERVER_ADDRESS` option defaulting to 127.0.0.1:9999
  • Added `REBINDING_PROTECTION_EXEMPT_HOSTNAMES` option
  • Fixed TLD detection to correctly identify 'site' and 'network' as public, not local

Breaking Changes

  • pkg/nameserver.GetDNSServers now returns []netip.Addr instead of []netip.AddrPort and returns an error

New Features

  • DNS over TLS connection pooling
  • Health server address configuration
  • Rebinding protection exempt hostnames configuration
  • Filter middleware logs blocked elements with reasons

Full Release Notes

## Features

- DNS over TLS now uses a pool of connections to re-use TCP connections when possible (#150)
- `HEALTH_SERVER_ADDRESS` option, defaulting to `127.0.0.1:9999`
- by default log i/o timeout errors are logged at debug level because these are fairly common
- `REBINDING_PROTECTION_EXEMPT_HOSTNAMES` option
- `pkg/middlewares/filter`: log blocked elements with a reason

## Fixes

- `internal/local`: "site" and "network" TLDs are public, not local
- `pkg/middlewares/localdns`:
  - do not log request twice on errors
  - do not debug log NXDOMAIN coded responses since these happen often especially with search domains
- `internal/support/ipv6`: handle Windows error message
- Grafana dashboard plain DNS section updated

## Go API breaking changes

- `pkg/nameserver`: `GetDNSServers`
  - does not return localhost IPs if no nameserver is found 
  - returns an eventual error
  - returns []netip.Addr instead of []netip.AddrPort since it can only be an ip address without port

## Maintenance

- Grafana JSON dashboard upgraded to newer schema version 3
- Fix documentation URLs and CI links check
- bump markdownlint from v11 to v21