@serve.zone/coredns
Verified native SmartDNS distribution for Pallet-owned node-local DNS. This component ships the existing SmartDNS managed daemon for Linux amd64 and arm64; it does not use the unrelated upstream CoreDNS project.
Issue Reporting and Security
For reporting bugs, issues, or security vulnerabilities, please visit community.foss.global/. This is the central community hub for all issue reporting. Developers who sign and comply with our contribution agreement and go through identification can also get a code.foss.global/ account to submit Pull Requests directly.
Distribution and startup
The npm package is an input to the node bundle builder and installer. It has no
JavaScript service entry point and no daemon runtime npm dependencies. Its
@serve.zone/coredns/manifest export identifies dist_binary/manifest.json.
Paths in that manifest are relative to dist_binary/; the manifest records each
file's size, SHA-256 and executable role, both architecture selections, and the
exact SmartDNS version/commit. The manifest must come from the verified package or
node release; its hashes alone do not authenticate an untrusted download.
Each architecture supplies coredns and unchanged upstream
coredns.tsrust-build.json. The daemon is a static native executable. Install it
and the complete notices as part of Spark's verified node bundle before admitting
workloads. Starting it then needs no image pull, registry, JavaScript runtime,
Cloudly connection or DNS lookup.
Pallet uses the published ManagedDnsServer class from
@push.rocks/smartdns/server with an explicit absolute binaryPath to the
installer-verified executable. That API starts coredns --management with owned
inherited pipes and joins its shutdown. A missing explicit path fails; it does
not select another binary. There is no separate network configuration listener or
configuration file. Spawning creates no DNS listener; start() binds the selected
address for UDP and TCP, refusing queries until a managed snapshot is applied.
Ownership and current integration status
Cloudly owns organization networks, memberships, aliases, policies and endpoint records. Pallet authenticates and persists complete revisioned authority through SmartData/SmartDB, validates time, binds workloads to kernel-enforced network policy, configures DNS and supplies CRI resolver/search settings. Spark installs the node bundle and supervises Pallet. This component owns the distributed native DNS execution; SmartDNS owns its reusable engine and management protocol.
The packaged daemon supports complete source-scoped views, atomic revisions, readiness-filtered record sets supplied by its owner, bounded validity, private negative answers, and permitted external forwarding. These are engine capabilities; this distribution does not authenticate Cloudly projections, persist network state, establish workload membership, enforce IP isolation, renew leases, or independently recover authority after a node reboot.
Cloudly/Pallet/Spark integration and the complete two-node workflow remain unfinished. The component qualification covers package identity, native startup, UDP/TCP queries, owner-selected views and revision changes. It does not establish cross-node connectivity, CRI DNS injection, offline SmartDB recovery or trusted time after reboot. Creating private aliases must remain separate from public DNS, ingress, host ports and mail configuration.
Building and qualification
pnpm install --frozen-lockfile
pnpm build
pnpm test
pnpm run check
The builder consumes the exact published SmartDNS version pinned in
binary/engine.json and the lockfile. It verifies both native hashes and clean
upstream provenance, preserves every pinned notice, and emits executable modes.
It changes only generated code/assets under dist_binary/ and disposable build
staging. No application state is stored there. Builds require one build owner at
a time. Run tests after the build is complete.
The build policy permits esbuild's native tool setup and declines Puppeteer's browser download; this component's qualification uses native Linux sockets.
Both architecture assets are verified; native socket tests execute the current supported Linux architecture. Publishing uses the configured GitZone workflow, with package archive executable roles explicitly declared. New DNS behavior must be implemented and released in SmartDNS before updating this distribution.
License and Legal Information
This repository contains open-source code licensed under the MIT License. A copy of the license can be found in the repository license file.
Please note: The MIT License does not grant permission to use the trade names, trademarks, service marks, or product names of the project, except as required for reasonable and customary use in describing the origin of the work and reproducing the content of the NOTICE file.
Trademarks
This project is owned and maintained by Task Venture Capital GmbH. The names and logos associated with Task Venture Capital GmbH and any related products or services are trademarks of Task Venture Capital GmbH or third parties, and are not included within the scope of the MIT license granted herein.
Use of these trademarks must comply with Task Venture Capital GmbH's Trademark Guidelines or the guidelines of the respective third-party owners, and any usage must be approved in writing. Third-party trademarks used herein are the property of their respective owners and used only in a descriptive manner, e.g. for an implementation of an API or similar.
Company Information
Task Venture Capital GmbH
Registered at District Court Bremen HRB 35230 HB, Germany
For any legal inquiries or further information, please contact us via email at hello@task.vc.
By using this repository, you acknowledge that you have read this section, agree to comply with its terms, and understand that the licensing of the code does not imply endorsement by Task Venture Capital GmbH of any derivative works.