Sign in

NLnet Labs

@nlnetlabs.bsky.social
266 followers 27 following 31 posts

Dutch #NonProfit foundation proudly serving the Internet community since 1999 with #OpenSource software for #DNS and #BGP. Applied research, open standards advocates, bridging technology and policy.

PostsRepliesMedia
Reposted by NLnet Labs
Terts Diepraam @tertsdiepraam.bsky.social · 28/05/2026
It's been a year since we announced Roto! So we're celebrating with the release of Roto 0.11 and a blog post! For those who are unfamiliar: Roto is a statically-typed, compiled, embedded scripting language for Rust by @nlnetlabs.bsky.social. blog.nlnetlabs.nl/one-year-of-... #rust #rustlang #roto
blog.nlnetlabs.nl
One year of Roto, the compiled scripting language for Rust
By Terts Diepraam Almost exactly one year ago, we announced Roto, a JIT-compiled embedded scripting language for Rust applications. A lot has happened since then that we'd like to tell you about! 💡A...
1134
NLnet Labs @nlnetlabs.bsky.social · 17/05/2026
Please pray to the live demo Gods over lunch so Ximon can show you our #DNSSEC signer Cascade in action this afternoon at #OARC46. We’ll cover incremental signing with IXFR in and out with TSIG, all on a YubiHSM we packed. 🤞
011
NLnet Labs @nlnetlabs.bsky.social · 27/02/2026
We’ve released NSD 4.14.1 with more compact data storage for improved memory efficiency. Check the release notes: www.nlnetlabs.nl/projects/nsd... Willem also wrote a blog post explaining the approach and measurements showing the reduced memory footprint: blog.nlnetlabs.nl/smaller-fast...
blog.nlnetlabs.nl
Smaller, faster: NSD's refactored RDATA storage and compile time memory reduction options
On the 4th of December, NSD 4.14.0 was released with refactored RDATA storage, reducing the memory footprint of NSD. In this post we'll show the effect of this refactoring, what sort of zones benefit ...
011
Reposted by NLnet Labs
Terts Diepraam @tertsdiepraam.bsky.social · 14/01/2026
We tagged version 0.10.0 of Roto! For those who are unfamiliar: Roto is a statically-typed, compiled, embedded scripting language for Rust by @nlnetlabs.bsky.social. Release notes: community.nlnetlabs.nl/t/release-ro.... I'll summarize the important features! 1/8 #rust #rustlang #roto
community.nlnetlabs.nl
Release: Roto 0.10.0!
We are happy to announce version 0.10.0 of Roto, the statically-typed, compiled, embedded scripting language! This release is packed with new features such as lists, for loops, type parameters and var...
152
Reposted by NLnet Labs
Terts Diepraam @tertsdiepraam.bsky.social · 05/01/2026
We now have a forum for Roto and the other @nlnetlabs.bsky.social projects, which should make it easier to ask questions and start discussions! You can also interact with it via email if you prefer. Check it out at community.nlnetlabs.nl!
community.nlnetlabs.nl
NLnet Labs Community
021
Reposted by NLnet Labs
Terts Diepraam @tertsdiepraam.bsky.social · 16/10/2025
I collaborated with @cirw.in at EuroRust to make a Zed extension for Roto! It's based on the tree-sitter grammar and supports syntax highlighting and generating an outline. It can be installed via Zed's regular extension manager. Thanks @cirw.in! cc @nlnetlabs.bsky.social #rust #rustlang
0112
Reposted by NLnet Labs
Terts Diepraam @tertsdiepraam.bsky.social · 06/10/2025
If you want to know more about how we at use Roto as @nlnetlabs.bsky.social , you can watch Luuk's great talk about Rotonda and Roto at NLNOG last week: www.youtube.com/watch?v=B9cE.... 3/N
youtube.com
NLNOG Day 2025: Luuk Hendriks - Collecting and analyzing routing information with Rotonda
YouTube video by NLNOG
101
NLnet Labs @nlnetlabs.bsky.social · 03/10/2025
OpenDNSSEC will reach End-of-Life in Oct 2027. Since 2010, it’s been a trusted DNSSEC signer, pioneering automated key management and zone signing. As operational needs evolved, maintenance became complex. Our focus now shifts to Cascade, a modern, efficient successor. nlnetlabs.nl/news/2025/Oc...
nlnetlabs.nl
News - End-of-Life Roadmap for OpenDNSSEC
OpenDNSSEC will reach end of life in two years, October 2027.
011
Reposted by NLnet Labs
Terts Diepraam @tertsdiepraam.bsky.social · 25/08/2025
And as always, I forgot the hashtags. How do feeds work again over here? Anyways, we did a Roto release! Check out this thread for the highlights. #rust #rustlang #opensource #roto
011
Reposted by NLnet Labs
Terts Diepraam @tertsdiepraam.bsky.social · 25/08/2025
Forgot to tag @nlnetlabs.bsky.social properly! Darn you Bluesky let me edit my posts!
021
Reposted by NLnet Labs
Benno Overeinder @bjo.bsky.social · 19/07/2025
Kicking off this weekend in Madrid, #IETF123 began with the #IETFHackathon on Saturday and Sunday. A fantastic way to start the week coding and connecting. Nearly 500 people registered and almost 60 projects. The Hackathon rooms are buzzing!
Whiteboard with Hackathon room layout and the projects.Picture of the Hackathon overflow room.Picture of main Hackathon room.
042
NLnet Labs @nlnetlabs.bsky.social · 16/07/2025
Unbound 1.23.1 is out — a security update fixing the Rebirthday Attack (CVE‑2025‑5994), affecting DNS resolvers with ECS servers replying without ECS. Details: nlnetlabs.nl/downloads/un... Release: github.com/NLnetLabs/un... Thanks to Xiang Li for reporting!
nlnetlabs.nl
001
Reposted by NLnet Labs
EuroRust @eurorust.eu · 30/06/2025
Need a fast, safe scripting language for your Rust app? Terts Diepraam and the team at @nlnetlabs.bsky.social couldn’t find one that fit. So they built their own. It’s called Roto. And you’ll be hearing all about it at #EuroRust25. 👇🏼 🧵1/3
141
NLnet Labs @nlnetlabs.bsky.social · 19/06/2025
We updated DNS-over-QUIC in Unbound #DNS resolver to use the latest release of ngtcp2, version 1.13.0. It now also supports OpenSSL 3.5.0. In addition, this change now calls the new performance increase init for the ngtcp2 crypto library. #DoQ #OpenSource github.com/NLnetLabs/un...
github.com
DNS over QUIC depends on a very outdated version of ngtcp2 · Issue #1296 · NLnetLabs/unbound
I'm trying to add support for DNS over QUIC in nixpkgs at NixOS/nixpkgs#417917, however the build fails because it depends on ngtcp2 0.19.2 whereas we are currently on 1.13.0 - therefore i would li...
021
NLnet Labs @nlnetlabs.bsky.social · 18/06/2025
When you make it to the top of Hacker News, you end up with lots of feedback that helps to improve your #OpenSource product. We're proud to introduce the latest version of our modular #BGP engine, Rotonda 0.4.2 'Bonjour des Pyrénées'. github.com/NLnetLabs/ro...
github.com
Release 0.4.2 'Bonjour des Pyrénées' · NLnetLabs/rotonda
Released 2025-06-18. With this release, Rotonda switches to version 0.6.0 of the roto library. While many things have improved behind the scenes and under the hood, there are no breaking or otherwi...
021
Reposted by NLnet Labs
Terts Diepraam @tertsdiepraam.bsky.social · 10/06/2025
We just released Roto 0.6.0! Roto is the JIT compiled, strongly-typed, embedded scripting language for Rust used by Rotonda. This release features many fixes, quality of life improvements and an assignment operator! github.com/NLnetLabs/ro... @nlnetlabs.bsky.social #OpenSource #rustlang #BGP
github.com
Release v0.6.0 · NLnetLabs/roto
We're happy to announce Roto 0.6.0, which includes many bug fixes, quality of life improvements and an assignment operator! We'd like to thank @algernon for opening 9(!) excellent issues over this ...
071
NLnet Labs @nlnetlabs.bsky.social · 04/06/2025
We're proud to launch "dnst", our #DNS toolbox for network operators. With the "domain" #Rust crate acting as the natural successor to the "ldns" library, with "dnst" we are offering a modern drop-in replacement for the most widely used "ldns" utilities. #rustlang blog.nlnetlabs.nl/introducing-...
blog.nlnetlabs.nl
Introducing dnst — a DNS Toolbox for network operators
By Alex Band More than two decades ago, NLnet Labs started the ldns library, with the goal of letting developers easily create RFC compliant DNS software in the C programming language. The library in...
032
Reposted by NLnet Labs
Terts Diepraam @tertsdiepraam.bsky.social · 30/05/2025
Small thread on recent developments with Roto! To recap, Roto is the statically-typed compiled scripting language we're working on at @nlnetlabs.bsky.social .
blog.nlnetlabs.nl
Introducing Roto: A Compiled Scripting Language for Rust
By Terts Diepraam We are working on an embedded scripting language for Rust. This language, called Roto, aims to be a simple yet fast and reliable scripting language for Rust applications. The nee...
131
NLnet Labs @nlnetlabs.bsky.social · 26/05/2025
...speaking about the Roto language: it was featured on the front page of Hacker News after @terts introduced it on our blog: blog.nlnetlabs.nl/introducing-...
blog.nlnetlabs.nl
Introducing Roto: A Compiled Scripting Language for Rust
By Terts Diepraam We are working on an embedded scripting language for Rust. This language, called Roto, aims to be a simple yet fast and reliable scripting language for Rust applications. The nee...
031
NLnet Labs @nlnetlabs.bsky.social · 26/05/2025
We've released Rotonda 0.4.1! It features improved support for RPKI route origin validation in the embedded `roto` language. github.com/NLnetLabs/ro...
github.com
GitHub - NLnetLabs/rotonda: Modular, programmable BGP Engine
Modular, programmable BGP Engine. Contribute to NLnetLabs/rotonda development by creating an account on GitHub.
030
Reposted by NLnet Labs
NLnet Labs @nlnetlabs.bsky.social · 22/05/2025
We spent 2024 working on 'domain', our #DNS library for #Rust, as part of a grant from the Sovereign Tech Agency. As this work finished up and we approached 2025, we took a closer look at the foundations and realized the best way towards a more ergonomic and efficient 'domain' was to rework them.
122
Reposted by NLnet Labs
NLnet Labs @nlnetlabs.bsky.social · 22/05/2025
Five months, several iterations, and tens of thousands of lines of code later, we're ecstatic to announce the release of domain v0.11.0. We'm so proud of the team, and Arya in particular. You can read about her experiences in this article. #opensource #rustlang blog.nlnetlabs.nl/overhauling-...
blog.nlnetlabs.nl
Overhauling Domain
By Arya K. Previously, we discussed the massive development our domain library underwent over 2024. However, the project has been around much, much longer than that – the very first commit was made a...
032
NLnet Labs @nlnetlabs.bsky.social · 22/05/2025
We spent 2024 working on 'domain', our #DNS library for #Rust, as part of a grant from the Sovereign Tech Agency. As this work finished up and we approached 2025, we took a closer look at the foundations and realized the best way towards a more ergonomic and efficient 'domain' was to rework them.
122
Reposted by NLnet Labs
Terts Diepraam @tertsdiepraam.bsky.social · 21/05/2025
Hey look! I've been working on a thing! It's a statically typed, JIT compiled, hot-reloadable, embedded scripting language. blog.nlnetlabs.nl/introducing-...
blog.nlnetlabs.nl
Introducing Roto: A Compiled Scripting Language for Rust
By Terts Diepraam We are working on an embedded scripting language for Rust. This language, called Roto, aims to be a simple yet fast and reliable scripting language for Rust applications. The nee...
0319
NLnet Labs @nlnetlabs.bsky.social · 24/04/2025
A new release of Rotonda, our composable, programmable #BGP engine, is now available. Version 0.4.0 'Bold and Undaunting Youth' features and #RPKI RTR component, as well as Route Origin Validation on incoming routes. github.com/NLnetLabs/ro...
github.com
Release 0.4.0 'Bold and Undaunting Youth' · NLnetLabs/rotonda
Released 2025-04-24. Breaking changes Roto filter names have changed, as dashes are replaced with underscores. New An RTR component is introduced, enabling Rotonda to receive RPKI information fr...
022
NLnet Labs @nlnetlabs.bsky.social · 24/04/2025
NSD 4.12.0 is now available. Our authoritative #DNS server now offers Prometheus metrics, along with several other enhancements. github.com/NLnetLabs/ns...
github.com
Release NSD 4.12.0 · NLnetLabs/nsd
This release introduces Prometheus metrics that can be configured with enable-metrics (see nsd.conf(5)). nsd 4.12.0 FEATURES: Merge #418: Support for DSYNC, EID, NIMLOC, SINK, TALINK, DOA, AMTRELA...
001
NLnet Labs @nlnetlabs.bsky.social · 24/04/2025
Unbound 1.23.0 is out! Our #DNS resolver now supports 'fast reload'—it reads new configs in a thread and only briefly pauses to apply them. Also includes Redis replica support, DNS Error Reporting, and bug fixes. nlnetlabs.nl/news/2025/Ap...
nlnetlabs.nl
News - Unbound 1.23.0 released
fast reload, redis replica, error reporting, and bug fixes.
011
NLnet Labs @nlnetlabs.bsky.social · 08/04/2025
In equal honour to his induction into the Internet Hall of Fame, we have honoured our colleague of many years, Jaap Akkerhuis, by naming our meeting room after him. Jaap’s response was heartwarming, but as modest as he is, he said a broom closet would also be fine.
A bronze plaque that reads "Jaap Akkerhuis-zaal" in the NLnet Labs' office.
042
Reposted by NLnet Labs
Sovereign Tech Agency @sovereign.tech · 21/02/2025
For 25 years, @nlnetlabs.bsky.social has made impactful contributions to secure, open, and resilient internet infrastructure. From DNS security to routing protocols, their work has shaped the digital world we rely on today.
171
NLnet Labs @nlnetlabs.bsky.social · 21/02/2025
Today's the day—NLnet Labs' 25th jubilee party! 🎉 As an independent non-profit, we keep making the Internet better & safer with #opensource & #openstandards. Used our #DNS or #routing software? Worked with us on #IETF, research, or policy? Share your story!
25 years of NLnet Labs logo: A globe with a circular band around it, featuring the text '25 Years of NLnet Labs'.
141
NLnet Labs @nlnetlabs.bsky.social · 03/02/2025
We need your help! We're making good progress with #XDP support for our #DNS software. However, to properly test it we need access to two metal boxes with 10Gb/s NICs that have XDP driver support, e.g. docs.cilium.io/en/latest/re.... Please contact us if you can help out. 💚
docs.cilium.io
034
NLnet Labs @nlnetlabs.bsky.social · 30/01/2025
As we make steady progress towards offering a full-fledged #BGP route collector later this year, we're excited to release Rotonda 0.3.0 'Hempcrete & Hawthorn'. #OpenSource #rustlang github.com/NLnetLabs/ro...
github.com
Release 0.3.0 'Hempcrete & Hawthorn' · NLnetLabs/rotonda
Released 2025-01-30. Breaking changes In the embedded roto the define and apply blocks are gone. Users can now define variables and functions throughout the script. Arguments to filter-maps in ...
022
NLnet Labs @nlnetlabs.bsky.social · 27/01/2025
Important commit of the day... #OpenSource #Anniversary github.com/NLnetLabs/.g...
043
NLnet Labs @nlnetlabs.bsky.social · 23/01/2025
Routinator offered support for #RPKI Autonomous System Provider Authorization (ASPA) as an experimental feature for quite some time. #IETF standardization has now progressed far enough to make #ASPA a core feature in Routinator 0.14.1. #OpenSource #OpenStandards github.com/NLnetLabs/ro...
github.com
Release 0.14.1 ‘Black Cats and Voodoo Dolls’ · NLnetLabs/routinator
This release fixes a crash when the file names listed in a manifest contain illegal characters. We recommend all users to upgrade to this version. New ASPA support is now always compiled in and av...
001
NLnet Labs @nlnetlabs.bsky.social · 23/01/2025
Routinator 0.14.1 is out, fixing CVE-2025-0638, where non-ASCII characters in the file names listed in an #RPKI manifest lead to a crash of Routinator. You should also note CVE-2024-12084, fixing a flaw found in the rsync daemon. Please update both applications. nlnetlabs.nl/news/2025/Ja...
nlnetlabs.nl
News - Routinator 0.14.1 ‘Black Cats and Voodoo Dolls’ released
CVE-2025-0638, less disk consumption, ASPA
012
NLnet Labs @nlnetlabs.bsky.social · 08/01/2025
Even without some PRs merged and not counting all the spin off #DNS projects, the amount of changes in our #OpenSource `domain` #rustlang library in 2024 is massive. git diff --shortstat 5f40b97 f826b82 369 files changed, 89151 insertions(+), 7007 deletions(-) blog.nlnetlabs.nl/domain-found...
blog.nlnetlabs.nl
Domain Foundations – The first of our five year vision
In this series we’ll update you on our accomplishments in 2024 and our future plans. First we will focus on the work on our domain library for DNS
000
NLnet Labs @nlnetlabs.bsky.social · 07/01/2025
2024 has been a pivotal year for us. Our vision for #DNS, our commitment to #rustlang and, in its wake, the influx of new talent, all combined with the support from @sovereign.tech, we’ve been able to make a giant leap forward in realizing our #OpenSource goals. blog.nlnetlabs.nl/domain-found...
blog.nlnetlabs.nl
Domain Foundations – The first of our five year vision
By Arya Khanna, Martin Hoffmann and Alex Band About a year ago, we unveiled our vision for the next five years of DNS at NLnet Labs. In this series of articles, we’d like to provide you with an updat...
042
NLnet Labs @nlnetlabs.bsky.social · 18/12/2024
We have released NSD 4.11.0. One notable feature is that configuration can be reloaded and evaluated on SIGHUP, when enabled with the new "reload-config" option. Also, #DNS cookie secrets will be reevaluated from config. nlnetlabs.nl/news/2024/De...
nlnetlabs.nl
News - NSD 4.11.0 released
SIGHUP reloads config, bug fixes.
001
NLnet Labs @nlnetlabs.bsky.social · 14/11/2024
Our #DNS toolkit for #rustlang using our domain crate is nearing completion. We'll offer tools to transform a DNSKEY RR to DS RR, create a #DNSSEC key pair, print out the NSEC3 hash for the given domain name, generate a DNSSEC signed zone, and more. github.com/NLnetLabs/dn...
github.com
GitHub - NLnetLabs/dnst: Reimplementation of important ldns programs
Reimplementation of important ldns programs. Contribute to NLnetLabs/dnst development by creating an account on GitHub.
002
Reposted by NLnet Labs
Sovereign Tech Agency @sovereign.tech · 14/03/2024
We’re happy to announce our investment in @nlnetlabs.bsky.social's domain project, expanding this comprehensive, memory-safe library for building privacy & security-conscious DNS applications. This is another step towards a safer and more resilient internet: www.sovereigntechfund.de/tech/domain
sovereigntechfund.de
Domain | Sovereign Tech Fund
022