4384c71e0e Clarify that gibdns-go is a provider library, not an installable DNS driver.
Point operators at the catalog and keep this README aimed at people writing providers.

Co-Authored-By: Cursor Grok 4.6 <grok@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-13 15:08:49 +02:00

gibdns-go

Go runtime for gibdns provider programs. It implements the exec-json binding, DNS presentation and equality, patch/replace semantics, preconditions, and TTL policy so individual DNS providers can stay small.

This is a library, not a DNS provider you install and run. Operators should install a provider from the catalog and follow Using gibdns. Use this module when writing a new provider.

Protocol Status
gibdns/draft-01 Supported

Official providers (Cloudflare, deSEC, Gcore) are built on this runtime.

Use

package main

import (
	"foundry.fsky.io/gibdns/gibdns-go"
	"foundry.fsky.io/gibdns/gibdns-go/provider"
)

func main() {
	provider.Main(provider.Implementation{
		Name:          "example-dns",
		Version:       "1.0.0",
		RecordTypes:   []string{"TXT", "TLSA", "HTTPS"},
		ZoneDiscovery: true,
		Preconditions: map[string][]string{
			gibdns.MethodRRSetPatch:   {gibdns.PreconditionIfRevision, gibdns.PreconditionIfAbsent},
			gibdns.MethodRRSetReplace: {gibdns.PreconditionIfRevision, gibdns.PreconditionIfAbsent},
		},
		NewBackend: func(config map[string]any, secrets map[string]string) (provider.Backend, error) {
			return newBackend(config, secrets)
		},
	})
}

A backend only needs GetRRset and PutRRset. Optional interfaces:

  • ZoneDiscoverer when ZoneDiscovery is true
  • MemberPatcher when ConcurrentSafePatch is true

Advertise TXT for ACME DNS-01 hosts such as gibcert, and TLSA if the DNS service can publish DANE records. See the protocol specification for the request model.

When a provider is ready, add it to the catalog.

Development

make test
make lint
S
Description
gibdns library for Go
Readme 0BSD
56 KiB
Languages
Go 99%
Makefile 1%