A RFC8484 DNS-over-HTTPS (DoH) server implementation in Zig using WolfSSL and nghttp2.
- Zig 0.16+
- wolfssl
- nghttp2
This project uses Nix to manage its development environment.
nix develop
Will drop you in a shell with zig and all build and runtime dependencies required.
Generate SSL certificates (or provide your own):
mkdir -p certs
openssl req -x509 -newkey rsa:4096 -keyout certs/server.key -out certs/server.crt -days 365 -nodes -subj "/CN=localhost"
Create a config.json (example):
{
"server": {
"listen_address": "127.0.0.1",
"listen_port": 8443
},
"dns": {
"server": "1.1.1.1",
"port": 53
},
"ssl": {
"cert_file": "./certs/server.crt",
"key_file": "./certs/server.key"
}
}Start the server:
zig build run
Point your browser to https://<listen_address>:<listen_port>/dns-query.
Build the image via the Nix flake:
nix build .#dockerImage
docker load < result
Run the container (requires config.json and certs/ — see Run):
docker run --rm -p 8443:8443 \
-v $(pwd)/config.json:/app/config.json \
-v $(pwd)/certs:/app/certs \
doh:latest
zig build test