Cascade
A friendly, stand-alone DNSSEC signing solution designed to communicate what it’s doing and is easy to interact with.
Cascade is currently in its first alpha version. We would love for you to get to know Cascade and are eager to hear your experiences so we can improve every aspect. Please consider the current Known Limitations.
Cascade has the following design goals:
- Flexibility
Run Cascade the way that you want: from a package or a Docker image, on-premise or in the cloud, with keys on disk or an HSM of your choice.
- Sensible defaults
Get started easily with default settings based on industry best practices.
- Controllability
Cascade gives you tight control over the DNSSEC signing process and offers validation hooks at each stage of the process.
- Observability
With Cascade you cut out the guesswork. You will know what the pipeline is doing and why, and what you can expect to happen next.
- Open-source with professional support services
NLnet Labs offers professional support and consultancy services with a service-level agreement.
Feedback
Our goal is to gather operator feedback. Don’t be shy and reach out by creating a GitHub issue, sending us an email, finding us in the NLnet Labs DNS channel on the DNS OARC Mattermost server, or mentioning us on Mastodon.
Examples of things we’re interested in:
If these documentation pages don’t answer your question, tell us what we missed.
Performance and memory usage are expected to improve but if you think it won’t meet your needs, tell us about your use case.
Not all intended functionality has been implemented at this point. If a feature that you need is missing, please let us know.
We are actively working to shape the user experience to operator needs. We have a lot more ideas for improvement and we’d love to hear yours too.
Do tell us about your positive experiences. We particularly appreciate hearing O/S, HSM and size/number of zones you worked with.