Blocky — a fast, lightweight DNS proxy and ad-blocker for your local network, with blocklists, allowlists, per-client rules, caching and Prometheus metrics. Deployed as a single host-networked Nomad service with a seeded config you can customize.
Needs nomad-pack on PATH. The script only adds the nomploy registry and runs this pack.
Source ↗ Project ↗ ★ 7k ⚑ Report an issue
Save as values.hcl, edit, then run:
# The name of the Nomad job.
job_name = "blocky"
# The Nomad namespace to deploy into.
namespace = "default"
# The datacenters to deploy to.
datacenters = ["*"]
# The Blocky container image. Pin a tag in production.
image = "spx01/blocky:latest"
# Host port for DNS (UDP + TCP). Point your network's DNS at this.
dns_port = 53
# Host port for the HTTP API / Prometheus metrics / query UI.
http_port = 4000
# Upstream DNS resolvers for the default group (DoH/DoT/plain).
upstreams = ["https://dns.quad9.net/dns-query", "https://cloudflare-dns.com/dns-query"]
# Blocklist (denylist) URLs applied to all clients.
blocklists = ["https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts"]
# Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
constraints = []
# Resources for the Blocky task.
resources = {
cpu = 300
memory = 256
}
| Name | Type | Default | Description |
|---|---|---|---|
| job_name | string | "blocky" | The name of the Nomad job. |
| namespace | string | "default" | The Nomad namespace to deploy into. |
| datacenters | list | ["*"] | The datacenters to deploy to. |
| image | string | "spx01/blocky:latest" | The Blocky container image. Pin a tag in production. |
| dns_port | number | 53 | Host port for DNS (UDP + TCP). Point your network's DNS at this. |
| http_port | number | 4000 | Host port for the HTTP API / Prometheus metrics / query UI. |
| upstreams | list | ["https://dns.quad9.net/dns-query", "https://cloudflare-dns.com/dns-query"] | Upstream DNS resolvers for the default group (DoH/DoT/plain). |
| blocklists | list | ["https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts"] | Blocklist (denylist) URLs applied to all clients. |
| constraints | list | [] | Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true". |
| resources | object | {
cpu = 300
memory = 256
} | Resources for the Blocky task. |
No variables match.
Blocky is a fast, lightweight DNS proxy and ad-blocker for your local network — blocklists, allowlists, per-client rules, caching, conditional forwarding and Prometheus metrics, all from a single small Go binary.
This pack runs Blocky as a single host-networked Nomad job with a seeded config.yml.
Point your router or devices at it for network-wide ad/tracker blocking.
nomad-pack run blocky --registry=nomploy
Then set your network's DNS server to <node-ip> (port 53). The HTTP API, query UI and
Prometheus metrics are on port 4000.
| Variable | Default | Notes |
|---|---|---|
dns_port |
53 |
DNS port (UDP + TCP) |
http_port |
4000 |
HTTP API / metrics / query UI |
upstreams |
Quad9 + Cloudflare (DoH) | Upstream resolvers for the default group |
blocklists |
StevenBlack hosts | Denylist URLs applied to all clients |
Edit upstreams / blocklists and redeploy to change them. For advanced setups
(allowlists, per-client groups, conditional forwarding, custom DNS records) edit the
rendered config per the Blocky docs.
The service is stateless apart from its blocklist cache; there is no database or volume.