Cookbook: dns-authoritative
An authoritative name server for one zone file, with dynamic updates written back to the file.
cargo run -p dns-authoritative -- examples/dns-authoritative/example.com.zone 127.0.0.1:5353
dig @127.0.0.1 -p 5353 example.com SOA +norecurse
dig @127.0.0.1 -p 5353 www.example.com A +norecurse
dig @127.0.0.1 -p 5353 anything.example.com A +norecurse # wildcard
dig @127.0.0.1 -p 5353 example.com AXFR # loopback only
dig @127.0.0.1 -p 5353 example.net A # REFUSED: not our zone
printf 'server 127.0.0.1 5353\nzone example.com\nupdate add new.example.com 60 A 192.0.2.77\nsend\n' | nsupdate
With DNS_UPSTREAM="8.8.8.8 1.1.1.1" names outside the zone are forwarded instead of refused (an AuthoritativeZoneHandler chained ahead of a ForwarderHandler). With DNS_TSIG_KEY=name:hmac-sha256:base64secret TSIG-signed transfers and updates are also accepted from any address (dig -y hmac-sha256:name:base64secret, nsupdate -y).
Source: examples/dns-authoritative. Zone loading, dynamic update, NOTIFY, transfers, TSIG and secondaries are described in DNS: Authoritative zones.