RATATOSKRATATOSK
Sign in

CoreDNS

v1.14.7Kubernetes Core
Aug 19, 2026

ACTION 1CHECK 3OTHER 42

A broad release with a `Go 1.26.6` dependency update, an ACL bypass correction, and changes to operator-visible defaults. It also contains numerous feature additions, behavior changes, and defect corrections across CoreDNS plugins.

Action needed (1)

Check if affected (3)

  • securityACL checks for autopath in plugin/acl

    Applies if you use plugin/acl and autopath.

    plugin/acl no longer lets autopath bypass ACL checks.

  • breakingCapped default connect attempts in plugin/forward

    Applicability is not stated in the release notes.

    plugin/forward now caps the default number of connection attempts.

  • breakingOpt-in fallthrough for unsupported types in plugin/hosts

    Applicability is not stated in the release notes.

    Unsupported type fallthrough in plugin/hosts is now opt-in.

All 42 other recorded changesvalue changes 16 · fixes 13 · additions 11 · constraints 2

value changes (16)

  • core: Normalize server block zones (https://github.com/coredns/coredns/pull/8320)
  • core: Pin numeric uid/gid for the nonroot user (https://github.com/coredns/coredns/pull/8316)
  • plugin/cache: Bind responses and entries to QCLASS (https://github.com/coredns/coredns/pull/8272)
  • plugin/cache: Do not cache SOA-less NODATA responses (https://github.com/coredns/coredns/pull/8232)
  • plugin/cache: Preserve AD when storing cache entries (https://github.com/coredns/coredns/pull/8438)
  • plugin/cache: Preserve monotonic time for TTL expiry (https://github.com/coredns/coredns/pull/8346)
  • plugin/file: Do not expand wildcard across a closer empty non-terminal (https://github.com/coredns/coredns/pull/8223)
  • plugin/file: Resolve each additional section target only once (https://github.com/coredns/coredns/pull/8286)
  • plugin/file: Return referrals after alias resolution (https://github.com/coredns/coredns/pull/8341)
  • plugin/file: Run additional processing for CNAME/DNAME answers (https://github.com/coredns/coredns/pull/8337)
  • plugin/forward: Fast-path string comparison in isAllowedDomain (https://github.com/coredns/coredns/pull/8385)
  • plugin/kubernetes: Copy Labels in Pod.DeepCopyObject (https://github.com/coredns/coredns/pull/8415)
  • plugin/kubernetes: Short-circuit matchPortAndProtocol and fast-path string match (https://github.com/coredns/coredns/pull/8344)
  • plugin/kubernetes: Skip zone serial bump on DNS neutral pod updates (https://github.com/coredns/coredns/pull/8338)
  • plugin/proxyproto: Apply an explicitly configured default policy evenwhen no allow list is present. (https://github.com/coredns/coredns/pull/8278)
  • plugin/rewrite: Preserve original request during rewrites (https://github.com/coredns/coredns/pull/8235)

fixes (13)

  • plugin/acl: Fix blocked clients from receiving cached DNS answers (https://github.com/coredns/coredns/pull/8289)
  • plugin/auto: Fix inverted arguments in duplicate-origin warning (https://github.com/coredns/coredns/pull/8317)
  • plugin/cache: Fix cache stale verification metadata race (https://github.com/coredns/coredns/pull/8366)
  • plugin/file: Fixes multi-primary AXFR zone contamination (https://github.com/coredns/coredns/pull/8367)
  • plugin/file: Fix panic on zero-valued SOA refresh (https://github.com/coredns/coredns/pull/8276)
  • plugin/file: Stop self-referential DNAME loops (https://github.com/coredns/coredns/pull/8418)
  • plugin/forward: Fix incorrect failover counter reset (https://github.com/coredns/coredns/pull/8277)
  • plugin/forward: Fix incorrect retry of local DNS message serialization failures (https://github.com/coredns/coredns/pull/8313)
  • plugin/forward: Fix issue in DoH health checks used a default TLS instead of the configured CA (https://github.com/coredns/coredns/pull/8279)
  • plugin/forward: Fix UDP forwarding so a malformed upstream datagram wont block valid ones later (https://github.com/coredns/coredns/pull/8287)
  • plugin/rewrite: Normalize exact cname rewrite targets and preserve all records (https://github.com/coredns/coredns/pull/8285)
  • plugin/secondary: Reset catalog members on ID change (https://github.com/coredns/coredns/pull/8281)
  • plugin/transfer: Collect all notify errors instead of shadowing (https://github.com/coredns/coredns/pull/8283)

additions (11)

  • core: Add connection-level concurrency limiting to DNS-over-QUIC (https://github.com/coredns/coredns/pull/8213)
  • core: Add max conn limit to https3 (https://github.com/coredns/coredns/pull/8187)
  • plugin/cache: Add prefer_positive stale policy (https://github.com/coredns/coredns/pull/8378)
  • plugin/cache: Configure stale TTL and failure recheck (https://github.com/coredns/coredns/pull/8411)
  • plugin/file: Handle empty non-terminal wildcard sources (https://github.com/coredns/coredns/pull/8386)
  • plugin/forward: Add http(2) host/authority header and TO server resolution (https://github.com/coredns/coredns/pull/8233)×2
  • plugin/secondary: Support catalog migration and member scoping (https://github.com/coredns/coredns/pull/8288)
  • plugin/shed: Add UDP overload protection plugin (https://github.com/coredns/coredns/pull/8312)
  • plugin/timeouts: Add maxtcpqueries option to bound queries per TCP/TLS connection (https://github.com/coredns/coredns/pull/8376)
  • plugin/tls: Manage certificates with ACME DNS-01 (https://github.com/coredns/coredns/pull/8310)

constraints (2)

  • plugin/kubernetes: Add support for topology-aware headless services via "az-pinned" subdomains (https://github.com/coredns/coredns/pull/8388)
  • plugin/trace: Support IPv6 service endpoints in trace plugin (https://github.com/coredns/coredns/pull/8410)
Add CoreDNS to your stack

A weekly email arrives when a release needs action. Like the security patches and breaking changes in this release.

Add to stack