Unbound resolver using root nameservers.
Responds only to IPs in internal subnet (192.168.0.0/24).
192.168.0.0/24
Also contains DNS entries for all physical hosts as {hostname}.local
{hostname}.local
Runs on a service user through podman.
Deployed with Ansible, source is here.