4SO GeoDNS flow: Observe traffic, Understand topology, Resolve by policy, Monitor health, Optimize decisions.

AUTHORITATIVE DNS / GLOBAL TRAFFIC

4SO GeoDNSDNS Control Plane with an Independent Serving Path

API-first management of DNS desired state, validation, immutable revisions, blue/green delivery, health-aware routing, DNSSEC and node lifecycle in a single process, while the query path remains independent of the Manager.

Authoritative DNSGlobal TrafficDNSSECBlue / Green

4SO GeoDNS components: a query path independent from the control path

  1. 1Resolver queryA query arrives from a resolver, carrying its ECS or resolver network.
  2. 2DNS nodednsdist → active PowerDNS blue/green runtime → local PostgreSQL state; no live Manager on the query path.
  3. 3Geo/ECS policyDeterministic priority over ECS, CIDR, ASN/organization and geography; arbitrary user Lua is rejected.
  4. 4Healthy regional endpointThe answer points to the healthy endpoint the policy selected for this query.
  5. 5Unhealthy endpointHealth is computed out of band; the node only reads a local versioned snapshot.
  6. 6ManagerFastAPI-backed Product API; PostgreSQL holds desired state, audit and the outbox.
  7. 7Immutable revisionsA worker and mTLS node agent stage the inactive color, read it back, then cut over atomically.
01PROBLEM & OUTCOME

Product problem

A small DNS change can have a large blast radius.

Authoritative DNS must be fast and always available, while its changes must be precise, auditable and reversible. GeoDNS separates the configuration path from the serving path.

01SERVING

Serving must not depend on the Manager

The query path stays on the DNS node and its last verified state.

02CHANGE CONTROL

No direct changes to the runtime

Records and policies first become a revision, then are staged and verified.

03TRAFFIC

Traffic policy needs trustworthy data

Endpoint health and eligibility come from accepted observations, not from simulated browser state.

04SECURITY

DNSSEC has its own lifecycle

Keys, signing, rollover and recovery must be as controlled as zone management.

02CAPABILITY SNAPSHOT

Capability snapshot

Zones, traffic and security in one control plane.

Beyond authoritative records, GeoDNS treats delivery, traffic management and node lifecycle as part of the same product.

01ZONES & RRSETS

Type-safe zones and records

Forward/reverse zones, typed RRsets and controlled import/export.

02REVISIONS

Immutable Revisions

Changesets, snapshot hashes and revisions for audit and rollback.

03BLUE / GREEN

Blue/Green Delivery

Stage on the inactive color, read back state, then cut over atomically.

04TRAFFIC

Global Traffic Management

Endpoints, pools, regions, health perspectives and answer policy.

05DNSSEC

DNSSEC lifecycle

Signing, DS evidence, rollover and restore/reconcile.

06TRANSFERS

Secondary / Transfer

TSIG, AXFR/IXFR, catalog zones and secondary provider lifecycle.

07NODE LIFECYCLE

DNS node operations

Onboard, drain, replace, remove and fleet rollout.

08OBSERVABILITY

DNS Observability

Health, metrics, alerts, incidents and synthetic DNS probes.

4SO

The normal query path stays short: Resolver → DNS node → active runtime → local state. No regular query depends on the Manager or a cross-region database to be answered.

03DEPLOYMENT PROFILES

Deployment model

From one Manager and one DNS node to multiple regions.

The minimum product topology is simple, and HA or multi-region is not a prerequisite; nodes and regions are added incrementally.

ProfileControl PlaneServing PlaneUse case
Basic1 Manager1 DNS nodeSimple, complete authoritative DNS setup
Multi-nodeCentral ManagerMultiple DNS nodesServing redundancy and controlled rollout
Multiple sitesSingle control planeNodes across multiple sitesFailure-domain separation and proximity to resolvers
Multi-regionCentral management with regional processesIndependent serving in multiple regionsGlobal traffic and broad resilience
04ARCHITECTURE

Architecture

The configuration path is longer; the serving path is deliberately short.

A DNS change must pass through validation, revision and delivery. DNS answers, however, are served directly from the node's verified runtime.

CONTROLPanel / Product APIAuthentication, domains, RBAC and typed validation.
↓
AUTHORITYDesired state / Revision / JobTransactional state, immutable revisions, audit and evidence.
↓
DELIVERYWorker + Node Agent over mTLSStage, state read-back, verify and atomic cutover.
↓
SERVINGAuthoritative DNS nodednsdist and the active PowerDNS runtime with verified local state.
LayerComponentResponsibilityFail-safe behavior
Product APIFastAPI + scoped RBACZone/RRset, traffic policy, node lifecycle and typed validationThe browser never mutates the DNS runtime directly
AuthorityPostgreSQL + transactional outboxDesired state, audit, job/revision stateMutation and event publication within one transactional boundary
DeliveryWorker + mTLS Node AgentStage inactive color, read-back, verify and atomic cutoverFailed delivery stops before serving
DNS EdgednsdistStable serving entry and selection of the active PowerDNS colorThe query path does not depend on the Manager
Authoritative RuntimePowerDNS blue/green + local PostgreSQLServes the last verified revisionA control-plane outage keeps DNS answering from the last healthy state
SecurityDNSSEC · TSIG · transfer policySigning, rollover and zone-transfer trustSecret material never enters Panel/Audit/Evidence
TECH

Geo-routing & Health Contract. DNS decisions are read from the compiled policy and a local snapshot; the query path never runs a network health check at answer time.

DomainInput / MechanismTechnical contract
Client localityECS or Recursive Resolver IPValid ECS is used when permitted; otherwise the resolver IP is the basis for selection.
Geo / network matchCIDR, ASN/Organization, Country/Subdivision/Continent/CityPrecise overrides and geography are evaluated by numeric priority in deterministic order.
Native GeoIPPowerDNS geoip backend + Country/ASN MMDBGeoIP sits alongside gpgsql; zone data is not moved from the primary authority into a YAML/GeoIP backend.
HealthTCP/UDP/HTTP/HTTPS/TLS/DNS/gRPC/ICMP probesHealth is computed outside the query path, and states such as HEALTHY/DEGRADED/SUSPECT/UNHEALTHY are recorded in a versioned snapshot.
Policy compilerStructured policy → trusted runtime materialArbitrary Lua is not accepted; the compiler produces reproducible output with a hash bound to the revision.
SimulationResolver/ECS/time/health/dataset inputsRule match, selected pool/endpoint, fallback path, answer and TTL can be simulated before publish.
ECS cache isolationPolicy-aware cache keyingAnswers that depend on the client network must not leak through the cache across unrelated ECS contexts.
05LIFECYCLE

Lifecycle

Every DNS change has an observable path.

Going from edit to publish is more than a few clicks; validation, revision, stage, state read-back and recovery each have a defined state.

01EditEdit
02ValidationValidate
03Build revisionSeal
04StagingStage
05State read-backVerify
06PublishCutover
07MonitoringObserve
08Rollback / recoveryRecover
06DNS PROFILES

Capability profiles

Authoritative DNS is more than a zone editor.

Every layer, from authoritative data to global traffic and security, has its own operational profile.

Authoritative DNSZONES

Zone and RRset management with revisions.

  • Forward / Reverse
  • Typed RRsets
  • Scheduled / templated changes
Traffic ManagementGTM

Answers based on endpoint and policy.

  • Pools / Endpoints
  • Geo / health policy
  • Maintenance windows
DNS SecurityDNSSEC / TSIG

Trust and transfer security inside the product.

  • DNSSEC signing / rollover
  • TSIG
  • Transfer policy
DNS node fleetDNS NODES

Lifecycle of serving nodes.

  • Enroll / mTLS
  • Drain / Replace
  • Fleet rollout
DeliveryBLUE / GREEN

Safe, reversible publishing.

  • Inactive staging
  • State read-back validation
  • Atomic cutover
RecoveryCONTROL PLANE

Protecting management state.

  • Backup / Restore
  • Release rollback
  • Disaster recovery process
07ACTION & WORKFLOW CONTRACT

Job, cutover and recovery flow

A job is replayed only when its side-effect boundary is known.

Mutations are idempotent and project-scoped; node mutation, fleet rollout and certificate rotation never stay open concurrently on the same node. Worker ownership is fenced with a lease and an execution epoch.

01QueueQUEUED
02RetryRETRY
03LeaseRUNNING + EPOCH
04StageVERIFY / CUTOVER
05SuccessSUCCEEDED
06FailureFAILED / CANCELLED
07RollbackROLLED_BACK
BLUE / GREEN CUTOVER

Stage on the inactive color

DNS read-back happens before the active color is switched.

DNS QUERY ENTRY
↓
ACTIVE
BLUE
⇄
STAGED
GREEN
↓
DNS
VERIFY
revision → stage inactive → authoritative read-back → atomic cutover
A failed stage does not change active serving.
HEALTH BRANCH

Primary or fallback based on the snapshot

The query path never runs a network probe at request time.

CLIENT CONTEXT
ECS / RESOLVER
↓
POLICY + HEALTH SNAPSHOT
↓
PRIMARY
HEALTHY?
PRIMARY
↙ ↘
FALLBACK
Health state is versioned; a stale snapshot can block policy.
DR LOOP

Readiness → Failover → Failback

DR actions are bound to the readiness hash and topology freeze.

PRIMARY
SITE
→
READINESS
GATE
↓
FENCE
+ HASH
↑
DR
SITE
←
FAILBACK
VERIFY
backup ready → approval → failover → serving verify → controlled failback
Stale readiness or unknown external state goes to reconcile.
ADDITIONAL OPERATIONAL FLOWS

Additional operational flows

Health and node replacement directly affect serving quality and need their own flows.

Action / FlowAdmission / PreconditionsExecution / LockSuccess CriterionFailure / Recovery
Publish Zone / RRsetTyped validation, revision and policy compile before deliveryStage on inactive color → node read-back → atomic cutoverAuthoritative answer/TTL and active revision confirmed from the serving pathA failed stage does not change serving; rollback to the preserved healthy color
Traffic PolicyStructured policy, priority and simulation without conflictCompiler material is versioned; health snapshot is consumed outside the query pathMatched rule/pool/endpoint and synthetic DNS behavior match the revisionArbitrary Lua is rejected; policy conflict fails before publish
Node Onboarding / ReplaceIdentity/mTLS, preflight and node mutation availabilityDurable job with node lock; onboarding/day-2/fleet/cert-rotation overlap is rejectedNode observed healthy and rollout eligibility clearNode onboarding failure does not become a generic retry; a fresh bootstrap may be required
DNSSEC / CertificateKey/identity lifecycle and approval for sensitive operationsStage/overlap/ack and owner-specific rotation workflowSigning/serving or certificate observation matches the expected generationStale rotation/concurrent fleet mutation rejected; secret material removed from the public job projection
Control-plane RestoreBackup must be READY, repository-verified and carry snapshot/hash evidencePreflight → approval → execution → cutoverRESTORED only after preflight binding and runtime verificationWorker interruption/unknown external state → RECONCILE_REQUIRED; blind retry prohibited
DR Failover / FailbackReadiness job, topology freeze, fencing, rollback and RPO acknowledgement requiredThe action is bound to readiness state/hash and profile revisionActive site/traffic/database state reaches the expected phaseStale readiness or topology mismatch rejected; failback allowed only from FAILED_OVER
FLOW

Retry classification is explicit to the operator: SAFE_TO_RETRY, RECONCILE_REQUIRED, FRESH_BOOTSTRAP_REQUIRED or FRESH_HEALTH_REQUEST_REQUIRED. Lease loss in disruptive workflows is never permission for blind replay.

08OPERATIONS CATALOG

Operations catalog

DNS operations are controlled in proportion to their blast radius.

Operators use the same product process and audit trail to change records, roll out nodes or manage DNSSEC.

Create / Edit ZoneZone and RRset management with validation and revisions.
PublishStage, state read-back and atomic cutover to the new version.
RollbackReturn to the preserved healthy color.
Traffic PolicyManage endpoints, pools and health-aware response policy.
DNSSECSigning, rollover and restore/reconcile.
Node onboardingEnroll and prepare DNS nodes with controlled identity.
Drain / ReplaceRetire or replace nodes without directly changing the zone runtime.
ObserveHealth, metrics, alerts and synthetic DNS behavior.

Run DNS with serving speed and the rigor of a distributed system.

4SO GeoDNS controls changes without putting the Control Plane in the DNS answer path.

All 4SO products →