cPanel DNS Cluster Architecture: Building Geographically Redundant High-Availability Nameservers in Pakistan

A complete step-by-step masterclass on deploying cPanel DNSONLY clusters. Learn how to configure active-passive vs mesh synchronization, eliminate single points of failure, harden BIND/PowerDNS, and deploy custom low-latency nameservers across Pakistan.

cPanel DNS Cluster Architecture: Building Geographically Redundant High-Availability Nameservers in Pakistan

When a client purchases web hosting or registers a domain name, DNS is the invisible foundation holding the entire infrastructure together. If a web server goes down, visitors see an error page. But if your authoritative nameservers go down, your domains disappear from the global internet entirely. Mail servers cannot resolve MX records, browsers fail with NXDOMAIN or DNS_PROBE_FINISHED_NXDOMAIN, and consumer trust evaporates immediately.

Yet, a staggering number of Pakistani hosting providers, agencies, and enterprise IT teams commit a fundamental architectural mistake: hosting nameservers on the exact same server as their websites and email accounts. When that single web server reboots or encounters a DDoS attack, both ns1.yourdomain.pk and ns2.yourdomain.pk crash simultaneously.

In this engineering guide, we walk through building a resilient, enterprise-grade cPanel DNS Cluster using free cPanel DNSONLY nodes. We will cover cluster topologies, installation, API key authorization, BIND vs. PowerDNS considerations, and network redundancy for Pakistani ISPs.


What is cPanel DNSONLY?

cPanel DNSONLY is a streamlined, lightweight distribution of the cPanel software stack designed purely to serve authoritative DNS zones. Because it does not run Apache, MySQL, MailScanner, or PHP-FPM, it consumes negligible system resources (under 512 MB of RAM) and requires no cPanel license fees.

When tied together into a DNS cluster:

  1. Web hosting servers running full cPanel & WHM act as Write-Only or Synchronize clients.
  2. Whenever a domain, subdomain, SPF record, or SSL validation TXT entry is added or edited on any hosting server, that change is automatically pushed via WHM API to all dedicated DNSONLY nodes in real-time.
  3. Global visitors query the dedicated DNSONLY nodes directly, insulating DNS resolution from web server load spikes.

For web hosting providers managing multiple production machines, dedicated physical infrastructure guarantees consistent DNS resolution times. Learn more about deploying bare-metal hardware on Dedicated Servers and locally routed nodes on Dedicated Servers in Pakistan.


Choosing the Right Cluster Topology

Before executing commands, you must choose the appropriate clustering topology for your fleet:

[Web Server 01 (cPanel)] ────(Write-Only)────┐
                                             ├──► [NS1-DNSONLY (Islamabad DC)]
[Web Server 02 (cPanel)] ────(Write-Only)────┤
                                             ├──► [NS2-DNSONLY (Karachi DC)]
[Web Server 03 (cPanel)] ────(Write-Only)────┘
  • Configuration: Web servers are configured to Write-Only to both nameserver nodes.
  • Nameserver Nodes: Configured to Standalone.
  • Advantage: Web servers do not receive foreign DNS zones from each other. If Web Server 01 has 1,000 domains and Web Server 02 has 500 domains, neither host carries unnecessary zone files. The nameservers hold the unified aggregate.

2. Mesh Synchronization (For Dual-Server Environments)

  • Configuration: Two servers synchronize bidirectionally with each other.
  • Risk: High chance of zone synchronization loops if both nodes edit the same domain simultaneously.

Step-by-Step: Installing cPanel DNSONLY on Rocky Linux / AlmaLinux 9

Deploy two fresh VPS or lightweight cloud instances (ideally in separate geographic facilities, e.g., Node 1 in Islamabad and Node 2 in Karachi or overseas).

Step 1: Set Hostname and Disable Conflicting Firewalls

On each nameserver node:

# Set proper FQDN
hostnamectl set-hostname ns1.yourhostingbrand.pk

# Disable SELinux temporarily and permanently
setenforce 0
sed -i 's/^SELINUX=enforcing/SELINUX=disabled/' /etc/selinux/config

# Ensure Perl and Curl are installed
dnf install perl curl bind-utils -y

Step 2: Download and Run the Official cPanel DNSONLY Installer

cd /home
curl -o latest-dnsonly -L https://securedownloads.cpanel.net/latest-dnsonly
sh latest-dnsonly

The installer runs unattended, compiling the minimal cPanel environment and configuring BIND or PowerDNS. Installation typically takes 8 to 15 minutes.


Step 3: Configuring the DNS Cluster in WHM

Once both DNSONLY nodes are installed, log into your primary production cPanel server’s WHM interface:

  1. Navigate to Home » Clusters » DNS Cluster.
  2. Click Enable DNS Clustering.
  3. Under Add a new server to the cluster, click Configure.
  4. Enter the Remote cPanel Hostname or IP (ns1.yourhostingbrand.pk).
  5. Enter the Remote WHM Username (root).
  6. Generate a Remote Server Access Hash or API Token from the DNSONLY node:
    • On the DNSONLY node, run:
      whmapi1 create_user_session user=root service=whostmgrd
      Or log into https://ns1.yourhostingbrand.pk:2087 and create an API token under Manage API Tokens.
  7. Under DNS Failure Options, select Keep DNS cluster online if this server goes down.
  8. Set DNS Role to Write-Only.
  9. Click Submit.

Repeat this process for your secondary nameserver (ns2.yourhostingbrand.pk).


Step 4: Synchronizing Existing DNS Zones

Once connected, push all existing DNS zones from your cPanel servers to the new cluster:

# On your primary cPanel web server:
/scripts/dnscluster syncall

To verify that the zone exists and responds authoritatively on your new nameserver:

dig @ns1.yourhostingbrand.pk yourdomain.pk +norecurse

The response should return status NOERROR with the flags: qr aa rd indicating an authoritative answer (aa).


PowerDNS vs. BIND: What Should You Use?

In WHM » Service Configuration » Nameserver Selection, you can toggle between PowerDNS and BIND:

Feature BIND (named) PowerDNS
Backend Storage Flat zone files (/var/named/*.db) SQLite / MySQL / BIND-backend
Memory Footprint Moderate Very Low
DNSSEC Support Complex manual key management Native 1-Click DNSSEC in WHM
High Concurrency Performance Good Excellent
Recommendation Legacy compatibility Recommended for all modern deployments

Switching to PowerDNS allows cPanel to automate DNSSEC key rollover, generating DS records that you can directly submit to PKNIC (.pk registry) or ICANN registrars.


Hardening Your Nameservers Against DNS Amplification Attacks

Public recursive DNS servers are frequent targets for DDoS reflection attacks. Ensure your authoritative nameservers refuse recursion for external IP addresses.

In /etc/named.conf or PowerDNS configuration:

options {
    recursion no;
    additional-from-auth no;
    additional-from-cache no;
    allow-query { any; };
    rate-limit {
        responses-per-second 15;
        window 5;
    };
};

Restart the nameserver service:

/scripts/restartsrv_named
HIGH-AVAILABILITY CLUSTER INFRASTRUCTURE

Build Rock-Solid, Unbreakable Nameservers in Pakistan

Never let a server reboot take down your client websites. Deploy multi-datacenter cPanel clusters on enterprise bare-metal infrastructure engineered for 100% uptime.

Rated 4.7 out of 5 stars based on 48 reviews on Trustpilot