Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Support
  3. can't install cloudron due to unbound issues

can't install cloudron due to unbound issues

Scheduled Pinned Locked Moved Solved Support
unboundinstallation
23 Posts 7 Posters 932 Views 7 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • girishG Offline
    girishG Offline
    girish
    Staff
    wrote on last edited by
    #21

    as @nebulon said please test host -t NS apple.com 127.0.0.1 on a fresh ubuntu + unbound. If this works, this is already a start . Next step is to use the unbound config at https://forum.cloudron.io/post/104349 . With that config in place, you have to test with host -t NS apple.com 127.0.0.150 . Here's a demo recording if it helps - https://asciinema.org/a/9mMqdLmgJ2X7vWgBUkQVAgB5i

    1 Reply Last reply
    2
    • potemkin_aiP Offline
      potemkin_aiP Offline
      potemkin_ai
      wrote on last edited by
      #22

      @nebulon , I'm quite confused as well - I realize it's a basic thing that, would it be broken, would affect everyone at all.

      Default unbound works on 127.0.0.1 indeed and so far I ended up with point-finger with firewall - it seems UDP requires 53 port to be open on the inbound firewall rules to be working - something you have on your iptables rules as well.

      For your reference - it's much easier to troubleshoot unbound with systemctl stop unbound && unbound -dd -vvvv as it start writing everything on the console, so we stop the guess work.
      Other common troubleshooting steps are ss -tulnp | grep 53 to see if there is anyone listening.

      @girish , thank you - for the time being I ended up disabling firewall completely to process with installation process.
      I believe I unexpectedly advanced with unbound server for the last 24 hours and will be looking to reconfigure it once the setup is done.

      It seems like unbound is only used for SpamHause and during setup. If the setup issue will resorted, only SpamHause issue will remain.

      girishG 1 Reply Last reply
      0
      • potemkin_aiP potemkin_ai

        @nebulon , I'm quite confused as well - I realize it's a basic thing that, would it be broken, would affect everyone at all.

        Default unbound works on 127.0.0.1 indeed and so far I ended up with point-finger with firewall - it seems UDP requires 53 port to be open on the inbound firewall rules to be working - something you have on your iptables rules as well.

        For your reference - it's much easier to troubleshoot unbound with systemctl stop unbound && unbound -dd -vvvv as it start writing everything on the console, so we stop the guess work.
        Other common troubleshooting steps are ss -tulnp | grep 53 to see if there is anyone listening.

        @girish , thank you - for the time being I ended up disabling firewall completely to process with installation process.
        I believe I unexpectedly advanced with unbound server for the last 24 hours and will be looking to reconfigure it once the setup is done.

        It seems like unbound is only used for SpamHause and during setup. If the setup issue will resorted, only SpamHause issue will remain.

        girishG Offline
        girishG Offline
        girish
        Staff
        wrote on last edited by
        #23

        @potemkin_ai said in can't install cloudron due to unbound issues:

        It seems like unbound is only used for SpamHause and during setup. If the setup issue will resorted, only SpamHause issue will remain.

        It's also used for DNS propagation checks (during app install, change location etc) and also verify validity of DNS records for Let's Encrypt. We cannot rely on caching resolvers because they would cache not found (NXDOMAIN) entries for very long periods of time.

        The recommendation is to keep all the outbound ports open - https://docs.cloudron.io/security/#outbound-ports .

        1 Reply Last reply
        0
        • girishG girish has marked this topic as solved on
        Reply
        • Reply as topic
        Log in to reply
        • Oldest to Newest
        • Newest to Oldest
        • Most Votes


        • Login

        • Don't have an account? Register

        • Login or register to search.
        • First post
          Last post
        0
        • Categories
        • Recent
        • Tags
        • Popular
        • Bookmarks
        • Search