FROM debian:stable-slim ENV DEBIAN_FRONTEND=noninteractive RUN apt-get update && apt-get install -y --no-install-recommends \ unbound \ unbound-anchor \ dnsutils \ ca-certificates \ && rm -rf /var/lib/apt/lists/* # Keep path compatibility with existing bind mounts in docker-compose.yml RUN mkdir -p /opt/unbound/etc/unbound /opt/unbound/etc/unbound/dev /opt/unbound/etc/unbound/var \ && : > /opt/unbound/etc/unbound/dev/null # Pre-create DNSSEC trust anchor used by the mounted unbound.conf. RUN unbound-anchor -a /opt/unbound/etc/unbound/var/root.key || true # Allow unbound daemon user to update trust anchors and write to chrooted /dev/null. RUN chown -R unbound:unbound /opt/unbound/etc/unbound/var /opt/unbound/etc/unbound/dev \ && chmod 666 /opt/unbound/etc/unbound/dev/null EXPOSE 53/tcp 53/udp CMD ["/bin/sh", "-c", "[ -s /opt/unbound/etc/unbound/var/root.key ] || unbound-anchor -a /opt/unbound/etc/unbound/var/root.key || true; exec unbound -d -c /opt/unbound/etc/unbound/unbound.conf"]