- General improvements
- Parallel download of only needed files at start
- Prettier console output with all streams merged (openvpn, unbound, shadowsocks etc.)
- Simplified Docker final image
- Faster bootup
- DNS over TLS
- Finer grain blocking at DNS level: malicious, ads and surveillance
- Choose your DNS over TLS providers
- Ability to use multiple DNS over TLS providers for DNS split horizon
- Environment variables for DNS logging
- DNS block lists needed are downloaded and built automatically at start, in parallel
- PIA
- A random region is selected if the REGION parameter is left empty (thanks @rorph for your PR)
- Routing and iptables adjusted so it can work as a Kubernetes pod sidecar (thanks @rorph for your PR)
39 lines
1.1 KiB
Go
39 lines
1.1 KiB
Go
package dns
|
|
|
|
import (
|
|
"fmt"
|
|
|
|
"github.com/qdm12/golibs/files"
|
|
"github.com/qdm12/private-internet-access-docker/internal/constants"
|
|
)
|
|
|
|
func (c *configurator) DownloadRootHints(uid, gid int) error {
|
|
c.logger.Info("%s: downloading root hints from %s", logPrefix, constants.NamedRootURL)
|
|
content, status, err := c.client.GetContent(string(constants.NamedRootURL))
|
|
if err != nil {
|
|
return err
|
|
} else if status != 200 {
|
|
return fmt.Errorf("HTTP status code is %d for %s", status, constants.NamedRootURL)
|
|
}
|
|
return c.fileManager.WriteToFile(
|
|
string(constants.RootHints),
|
|
content,
|
|
files.FileOwnership(uid, gid),
|
|
files.FilePermissions(0400))
|
|
}
|
|
|
|
func (c *configurator) DownloadRootKey(uid, gid int) error {
|
|
c.logger.Info("%s: downloading root key from %s", logPrefix, constants.RootKeyURL)
|
|
content, status, err := c.client.GetContent(string(constants.RootKeyURL))
|
|
if err != nil {
|
|
return err
|
|
} else if status != 200 {
|
|
return fmt.Errorf("HTTP status code is %d for %s", status, constants.RootKeyURL)
|
|
}
|
|
return c.fileManager.WriteToFile(
|
|
string(constants.RootKey),
|
|
content,
|
|
files.FileOwnership(uid, gid),
|
|
files.FilePermissions(0400))
|
|
}
|