
9/15/2020 · Alex Fattouche
What this post added
This post details the implementation of Cloudflare's Secondary DNS service, including its microservice architecture (Zone Transferer, Zone Transfer Scheduler, Rest API, Notify Listener) communicating via Kafka. It describes the migration from Mesos Marathon to Kubernetes, addressing challenges related to distributed reliability and IP allowlisting by proxying egress traffic with Shadowsocks-libev. It also covers protecting the Notify Listener from attacks by leveraging Cloudflare's DDoS protection and Spectrum.