Zonemaster on Ubuntu 24.04 LTS
بواسطة cloudimg
Zonemaster, the open source DNS delegation and DNSSEC health checker, on Ubuntu 24.04
This is a repackaged open source software product wherein additional charges apply for cloudimg support services.
Zonemaster by cloudimg
Deploy your own DNS delegation and DNSSEC health checker on your own Azure infrastructure in minutes. This image delivers Zonemaster - the checker maintained jointly by The Swedish Internet Foundation (IIS) and AFNIC - as the official upstream all-in-one build, so a web GUI and a JSON-RPC API are answering the moment the VM finishes its first boot.
What This Image Gives You
Give Zonemaster a domain and it investigates the zone from the root of the DNS tree down to the domain's own authoritative nameservers, running the full Zonemaster test suite across the Address, Basic, Connectivity, Consistency, Delegation, DNSSEC, Nameserver, Syntax, System and Zone modules. It returns a graded report that marks every finding as info, notice, warning, error or critical, so you can see exactly what is right and wrong with a zone's delegation and DNSSEC. The same backend is available as a JSON-RPC API, so you can automate checks from your own scripts and pipelines.
Registrars, hosting providers and DNS operators use Zonemaster to validate delegations, catch broken or expiring DNSSEC, and check zones before and after changes.
Why This Image Instead of Manual Installation
Zonemaster is a multi-repository Perl project - an engine, a backend with a JSON-RPC API and a test-agent daemon, a results database, and a web frontend - that normally has to be assembled and wired together by hand. This image delivers the official upstream all-in-one container, pinned by digest and captured into the VM, orchestrated by Docker Compose under systemd and fronted by nginx:
- The official Zonemaster all-in-one image (CLI, Backend, GUI and Engine), pinned by digest
- A web GUI for running tests and a JSON-RPC API for automation, both on one VM
- The container published to the loopback interface only, with nginx on port 80 in front
- An SQLite results database seeded empty on first boot, with no test data carried in the image
Secure By Default: A Unique Credential, Not An Open Instance
Zonemaster has no built-in login, and its public instances are open. This image is not left open. On first boot, before the port is reachable, a unique HTTP Basic Auth credential is generated for your instance, so the web GUI is protected from the moment it answers. A start-time guard refuses to serve with a placeholder or example credential, and the credential is written to a root-only file on the VM. Two independent boots produce two different credentials.
Secure By Default: The Backend And Database Stay Off The Network
The backend JSON-RPC API, the test-agent daemon and the SQLite results database run inside the container and are never published on a routable port. Only the authenticated web front door on port 80 is reachable from the network; the internal services answer only on the container's own loopback.
Getting Started
Launch the image, read the per-instance web credential from /root/zonemaster-credentials.txt, browse to the instance address, sign in with the HTTP Basic Auth credential, enter a domain and run your first graded DNS and DNSSEC health check. The same test is available over the JSON-RPC API behind the same credential.
Licensing and Pricing
Zonemaster is licensed under the BSD 2-Clause License, copyright The Swedish Internet Foundation and AFNIC, and is free. There is no per-seat fee. The cloudimg charge of 0.04 US dollars per vCPU hour covers packaging, security patching, image maintenance and 24/7 expert support.
cloudimg Support
24/7 technical support by email covers deployment, domain and certificate setup, running and reading domain tests, using the JSON-RPC API, changing the web credential, adding TLS and your own domain, and upgrades.
cloudimg is not affiliated with or endorsed by the Zonemaster project, The Swedish Internet Foundation or AFNIC. All product and company names are trademarks of their respective holders.