Live data from Hacker News

Kea 3.0, our first LTS version

isc.org

11–20 of 50 posts

Re: Kea 3.0, our first LTS version

#11
I wonder when this will make it into pfsense... The transition to kea has been a bit of a mess with tons of bugs. Thankfully it's controlled by an option, and it seems like 2.8.0 knocked out quite a few of them

Re: Kea 3.0, our first LTS version

#12
I have a positive ending Kea story. We deployed 20,000 PS5 APUs (AKA: AsRock BC-250) each is a individual blade computer that was PXE booted.

We started to see strange behavior on the network and it took a bit of trial and error to figure out what was going wrong. Eventually, we traced it down to dnsmasq being unable to keep up with all the DHCP UDP traffic regardless of how we tuned the kernel/networking buffers.

Switched to Kea and all of our problems magically went away.

Re: Kea 3.0, our first LTS version

#13
post #11

I wonder when this will make it into pfsense... The transition to kea has been a bit of a mess with tons of bugs. Thankfully it's controlled by an option, and it seems like 2.8.0 knocked out quite a few of them

Is opnsense ahead for this then? Or same

Re: Kea 3.0, our first LTS version

#16

I have a positive ending Kea story. We deployed 20,000 PS5 APUs (AKA: AsRock BC-250) each is a individual blade computer that was PXE booted. We started to see strange behavior on the network and it took a bit of trial and error to figure out what was going wrong. Eventually, we traced it down to dnsmasq being unable to keep up with all the DHCP UDP traffic regardless of how we tuned the kernel/networking buffers. Sw…

Wow, I didn't know the BC250s were used at such scale. I bought two to play with for dirt cheap, but haven't gotten around to it yet.

Are they primarily used for mining?

Re: Kea 3.0, our first LTS version

#17
post #2

I’ll google it in a moment, but skimming those notes, I have no idea what Kea is.

Won't take long, ISC doesn't do 'much' but they do it well

I remember Dan Bernstein (djb) being scathing about BIND. To the extent of writing his own DNS suite. Is that all ancient history now?

Re: Kea 3.0, our first LTS version

#18

Earlier quoted context omitted.

Won't take long, ISC doesn't do 'much' but they do it well

I remember Dan Bernstein (djb) being scathing about BIND. To the extent of writing his own DNS suite. Is that all ancient history now?

I'll let everyone make their own judgement :) https://en.wikipedia.org/wiki/Djbdns

Find something as popular that hasn't been scathed-about; I'll wait

Re: Kea 3.0, our first LTS version

#19
post #13
post #11

I wonder when this will make it into pfsense... The transition to kea has been a bit of a mess with tons of bugs. Thankfully it's controlled by an option, and it seems like 2.8.0 knocked out quite a few of them

Is opnsense ahead for this then? Or same

I don't follow pfsense too much but my understanding is OPNsense typically brings in package updates faster as they have a more frequent update cycle. I can't speak too much to bugs as I haven't migrated to Kea but imo some core functionality wasn't there until recently. And Dnsmasq seems like a better fit for me anyway, which is where I'll migrate to.

From the 25.1.6 OPNsense May update notes:

> Last but not least: Kea DHCPv6 is here. And with it full DHCP and router advertisement support in Dnsmasq to bridge the gap for ISC users who do not need or want Kea. We are going to make Dnsmasq DHCP the default in new installations starting with 25.7, too. ISC DHCP will still be around as a core component in 25.7 but likely moves to plugins for 26.1 next year.

https://docs.opnsense.org/releases/CE_25.1.html#may-08-2025

Re: Kea 3.0, our first LTS version

#20
post #13
post #11

I wonder when this will make it into pfsense... The transition to kea has been a bit of a mess with tons of bugs. Thankfully it's controlled by an option, and it seems like 2.8.0 knocked out quite a few of them

Is opnsense ahead for this then? Or same

I've been using it on opnsense since the first version it was released in. I aggressively switched because wanted to ditch my weird setup to do multi subnets (forwarding though a l3 switch). Haven't had any issues.
Post reply on HN