SpatiumDDI — open-source DDI (DNS/DHCP/IPAM) I've been building, looking for feedback

Hi everyone,

Long-time viewer of Tom’s channel, first-time poster here. I’m Zachary, a sysadmin from Montreal, and I’ve been building an open-source DDI platform in my spare time that I wanted to share with this community since you’re exactly the people who’d have opinions about it.

SpatiumDDI: GitHub - spatiumnorth/spatiumddi: Open-source DDI platform — unified DNS, DHCP, and IP Address Management. Runs its own BIND9 / PowerDNS / Kea service containers, with a FastAPI control plane and React UI. · GitHub

It’s DNS, DHCP, and IPAM unified under one control plane and API. Apache 2.0, no telemetry. The itch I was scratching: there’s great open-source point tooling (NetBox for IPAM, BIND/PowerDNS, Kea) but nothing pulling them into a single pane the way the commercial DDI platforms do — and Infoblox/EfficientIP pricing puts those out of reach for smaller shops, which is most of us here.

How it works in brief: FastAPI + PostgreSQL control plane is the source of truth. It deploys and manages the DNS/DHCP service containers itself (BIND9, PowerDNS, Technitium, Kea) instead of just templating configs for external servers, and it can also manage existing Windows DNS/DHCP agentlessly over WinRM. Hostname change in IPAM propagates to DNS, reservation propagates to DHCP. The agents cache last-known-good config locally and keep serving if the control plane goes down. Deploys via compose, k8s, or a bootable appliance image.

Honest status: it’s beta. Running in my lab and a few friendly networks. Full disclosure — I also run a small company (SpatiumNorth) that offers support/deployment around it, but the software itself is 100% open, no gated features.

What I’d actually love from this crowd: tear into the architecture. Especially from the MSP folks — what would break in a multi-client deployment, and what’s missing before you’d trust it on a client network? Issues and PRs welcome on the repo.

Thanks for reading, and happy to answer technical questions.

I’m trying to figure out what problem you are trying to solve. All I see is 3 services tired together with a webUI.

The problem is when you’re working in large orgs like education, healthcare, large enterprise it is impossible to maintain three seperate environments (DHCP, DNS, IPAM) and expect that someone can just copy/paste the information between them. I work in higher ed and I use our commercial IPAM tool on a daily basis. It would be impossible without it.

That said, maybe it is not for everyone but there is a very large user base out there for these products. If you look into commercial DDI solutions you’ll see they are very over priced and out of reach for the people that really need them.

So I get your point that you think it is just a webUI but there is a lot of background stuff going on as well to make sure everything is in sync. There are also integrations with many platforms like routers, firewalls, cloud, etc.

Looks like I would fall under your Medium support tier. If you want feedback on the architecture, based on what your site shows it looks pretty good. Your DNS/DHCP support solid services (bind9 & kea), and it looks like you run them in containers (presumably rootless). This is basically my setup.

You’d have to sell me on the IPAM service. I’ve never seen the value with it. My domain users are easy enough to find by the DC DNS, my servers/printers/network devices are statically assigned DHCP, and I just don’t care about IP management with my student and guest networks. Those networks are all just chromebooks and BYODs. I don’t know why I should care about the IP management with those networks after I make sure the subnet is big enough for the site in question. Let me know what I’m missing.

Maybe IPAM becomes super useful for sites over 10k users? I’m not sure why that would change my thinking, but I’m happy to learn. I imagine this is a tough sell the larger your enterprise market gets. To be honest, you would have to blow my mind to get me to move away from my current bind9 & kea infrastructure. Maybe I’m dumb and IPAM is the big selling point. But apart from that, putting a GUI in front of DNS & DHCP does the complete opposite for me. I just don’t want to add another giant stack of code to trust for something so simple and core to my network. The only management tools I have to trust (and keep updated) are vim and the gnu coreutils. Once a person gets good at those tools they are better than any GUI ever is.

Thanks for the feedback, it has been really difficult getting visibility on our project, it is a hard niche to fill.

Yes, we are running Bind & Kea under the hood, what is different is we have an agent running along side of them that are constantly monitoring and updating them to keep them in sync. We also support HA and failover as well as multiple server groups for both so for example if you wanted to have a seperate internal/external DNS server group you can do that.

As for the IPAM service I’ll speak from experience. I work at McGill University where we a very large network including switches, access points, UPSes and not to mention all the servers spread across our whole network. Every major faculty manages their part of the network and we give them deligated access into our current IPAM tool. I would say that the tool is used daily to allocate, monitor, validate, etc.

It is possible your network is not as big or as complicated, but if you are managing services that rely on DNS entries and making sure they line up with DHCP then a DDI solution is what this provides.

Since our project is open source, you can give it a try in any container environment you want, try our VM appliance or even try the demo in Github code spaces.

Before we had DDI at McGill we used static Bind configs and windows DHCP and a custom SQL database for IP tracking, it was really hard to manage but now that everyone who needs access has access, it is much easier.

In our tool we’ve also built in approvals so you can give access to people who ‘might’ know what they’re doing but you still have the final word.

Also, we are not trying to hide any of the services running underneath, if you want to go under the hood and look at how Bind and Kea are configured you can go into the container or even see the generated config through the gui. In the appliance you even have access to run the kubectl commands to see how kubernetes is managing everything under the hood.

Thanks for the feedback, hope you have a chance to give it a try!

Zachary

I agree with @strongbad’s assessment. Most enterprise environments already run Active Directory with integrated DNS and DHCP, so I would want to understand how SpatiumDDI coexists with AD-integrated zones in practice, and what the security posture looks like for managing Windows servers over WinRM, including the permissions required for the service account.

I would also like to see a clearer case for positioning this as a replacement rather than a complement to existing tooling. Many shops already use NetBox as their IPAM source of truth, so an integration path with NetBox may lower the barrier to adoption more than asking teams to migrate.

On the DHCP side, I would be cautious about any design that encourages DHCP on sensitive segments. Several of the environments I have supported required static addressing on restricted networks, and those segments would need to be documented in IPAM without DHCP involvement at all.

To be clear, this is not a criticism of the project itself. I am offering the perspective of someone who has spent over 15 years in large enterprise environments, where the bar for replacing core infrastructure services is very high. For the smaller shops and MSPs you are targeting, the calculus may be quite different, and I will be interested to see how it develops.

@xMAXIMUSx Thanks for the reply. In our environment we have a VERY large AD infrastructure (295K users, 132K groups) and while AD still handles the ad zone, our DDI infrastructure hadles all the requests for our user population (wired, wireless, servers, etc). We hide our campus zone behind our DDI infra and our DDI infra can manage it as well.

The way we’re trying to position our tool for now is not a complete replacement, it still has a lot of work to get up to that level of a tool, but for now it should be able to compliment or enhance the your view of your network.

We did add an integration with Netbox so you can import all your IPAM records from it into our tool. I was always dissapointed that IPAM didn’t have native DHCP/DNS integration and I’ve been wanting to write a tool like this for the last 10 years, Claude came to my rescue. This tool is not AI slop, I’ve been working on it very hard since April this year staying up many late nights and weekends.

I’ve got 30 years of experience in all forms of networking and server management so I’m trying ot put all of my knowledge into this tool and keeping it open source as I believe tools like this should not be locked behind a paywall.

Your question about WinRM is a good one, with our tool you have bi-directional control of both DHCP & DNS inside windows using a service account, nothing to install on the Windows side and I think if I remember correctly we can set it up in read only mode but I’d have to check to be sure.

Thanks for the feedback, all feedback is good feedback :wink:

Your setup is clearly an order of magnitude larger than mine. At 300k devices, you are solving problems that I don’t have. With that said, if you want to play down in the small single digit thousand-user base, here are some questions a rube like me still has.

Isn’t this DDNS in kea?

With DDNS, wouldn’t the lone kea config file be the single source of truth? Assuming you don’t use your DC for DHCP (which is my case, and presumably big deployments).

I should admit, I haven’t setup DDNS in kea yet. For static assignments, I still have to update two files (kea & the zone file) like a caveman. This maybe happens a half dozen times a year. And for most of them I’d still need/want to make static assignments even with DDNS. But to have DDNS would still be simpler. And cooler.

Plus, wouldn’t this allow departments to control their own devices within their subdomain? That would be my first attempt to tackle the delegation issue. If somebody important wanted to read the full IP list, then I’d awk/grep all the info from kea to a text file that they could read. Set that up on a schedule and be done with it. Maybe this idea wouldn’t be good enough at scale?

This sounds like views in bind. I use about eight views in my hidden master config. One external view and the rest internal. These are all individually farmed out to multiple secondary/slave servers across multiple sites. Bind is great.

I also think where it is a big miss are the subnets that don’t have DHCP. Mainly because it’s a security risk and compliance. This product wouldn’t fit in that environment.

Really, the only place it does fit is workstations. To the point where I can simply find that quick enough in AD DNS. Or ping their workstation by DNS name.

That is why I am finding it hard to justify what problem is trying to be solved.

@xMAXIMUSx — the no-DHCP subnet point is worth correcting, because it’s a design decision, not a gap. DHCP is optional per subnet in SpatiumDDI. A static-only segment lives in IPAM with no DHCP scope at all. Every address manually allocated with owner and purpose attached, and DNS records still generate from the IPAM record and sync to the DNS servers. No DHCP server ever touches the segment.

Honestly, that’s the compliance-friendly mode: when an auditor asks “show me everything on this segment and who owns it,” that’s one query. In most shops the honest answer is a zone file, a spreadsheet, and whoever’s memory is still employed there. AD DNS covers your domain-joined workstations, sure — it says nothing about printers, switches, cameras, Linux boxes, and everything else that actually causes IP conflicts.

@strongbad — on DDNS: you’re right, and I’ll concede it cleanly. Kea’s DDNS does the DHCP→DNS sync for leased clients, and if that’s your whole problem, it’s enough — genuinely. What it never sees is everything else: your statics (your own words — two files, like a caveman), reservations, subnets with no DHCP, and the address inventory itself. That’s also why the Kea config can’t be the single source of truth even in your shop. Your DC’s DNS, your zone files, and your eight views already hold truth Kea knows nothing about. “Source of truth” just means one place that knows about all of it, including the stuff no daemon assigns dynamically.

Your delegation idea is basically sound for DNS records — but subdomain delegation doesn’t allocate IPs or make reservations, and nsupdate keys give you no audit trail, no validation, no guardrails when a department fat-fingers something. And then the awk/grep report shows you leases. Statics, reservations and planned space aren’t in the lease file. Is it good enough at your scale? Probably but it breaks the day the person who wrote the awk script isn’t around.

On views: no argument at all, BIND views are great and you clearly know them. SpatiumDDI’s server groups are the same idea — the difference is one management plane pushing consistent configs to every server instead of hand-maintaining the hidden master. The daemons stay BIND and Kea either way. That said, we support views as well.

Hopefully this helps, let me know if you have any more questions or suggestions :wink:

This has to be the most AI generated reply I have ever seen. :-1:

1 Like

Its frustrating isnt it? Everyone with paid Claude subscription is developer these days. I see that op has shared his github page, i opened it, saw Claude in the list of code contributors, and closed the page immediately. Ai cancer is everywhere. And so called “developers” dont even bother replying themselves, they use ai for that too. This is next level lazy and insulting.

AI or not, I’ll reply with some of my thoughts. But your response does make more sense if AI wrote it.

Adding DDNS would allow me to know the FQDN for any reservation I make in the single kea file. I use static reservations for almost everything. The very few manual static assignments I make are added as comments to the kea file, so that file remains my single source of truth (grep’able). With DDNS I should be able to get DNS out of that file too. I’d have the static IP, subnet, hostname, and subdomain (ddns-qualifying-suffix) for all devices worth knowing about. And my kea logs for the rest not worth knowing about. I think I sold myself on this idea.

Your second paragraph to me is off the mark. Same with your last. I was going to reply, but I won’t bother.

Are you saying you statically assign most fixed IP assets? That is a lot of work for a relatively modest risk, IMO. Or, at least it is a risk that can be mitigated. Unless auditors are forcing you to do this.

Honestly, this project doesn’t give any value to any serious enterprise infrastructure. I don’t believe a word this dude has said about the project or how he has it implemented this in a “295k” user environment.

1 Like

Yes I did use AI to help me in the last response as I am quite busy and the answers were a lot for my brain to handle so I needed some help, sorry if you feel that I ‘cheated’. Yes, we are using Claude to write the solution. AI is a tool like any other, doesn’t mean the people using it don’t have skills it just helps us advance the project along a lot faster with a smaller team.

Building this DDI solution has been a dream of mine for the past 10 years and now with AI as a tool (that I’ve been paying for out of my own pocket for the past 6 months for the 5x plan) I’ve put a lot of work into it and stayed up a lot of late nights and weekends and time away from my family. My friend Eric (the other co-founter) and I work together at McGill and he is also contributing heavily to the project. He’s built a whole QA test environment that does load testing, soaking, finding issues, etc and has been finding and fixing many issues that we could not have though of ourselves.

I know people have strong options on AI, but like I said, it is a tool and if you know how to use it the right way you can get great things acomplished. I’m not trying to change your mind on how you see things, that’s just my opinion.

Now to answer some of the questions, in our network that I run we have a full mix of things, static, dynamic, static dhcp, ddns, etc, all of it and more. Having the tie in between DHCP and DNS is one of the nice things that DDI gives you as out of the box Bind and Kea don’t talk to each other without scripts.

As for our environment at McGill, we are not using Spatium DDI and we probably won’t use it for a few years as we have a signed contract with an enterprise DDI solution. I will not force McGill to use it, that is not up to me but it will hopefully become an option when the time comes.

I did not write this tool FOR McGill, I just saw how expensive the commercial solutions were and was surprised there was no open source alternative and wanted to give people the opportunity to have access to a tool like this when they can’t afford it.

Anyways, hopefully that answers some of your questions, I’ll try not to use AI anymore in my answers :wink:

Thanks

We have no idea who you are, and what kind of skills you have. Majority of people would never be able to tell if “your product” is fully ai generated, or you and your buddies wrote the code, understand the code, and you used ai only to assist you. You have to understand that anyone with the little bit of money can do what you did. You bring absolutely nothing to the table, and to be honest, whole idea looks ai generated as well. And using ai to reply is not a good look either. For all we know, you could be just a spam bot pushing ai slop.

1 Like

I’m Zachary McGibbon, feel free to look me up on LinkedIn, McGill directory and even on the Canadian Government corporations site for our company that we started so we could offer support. I won’t put links here so that way you can see on your own.

I’m not an AI bot so I’ll leave it at that.

That was not a question. I dont care who you are and what you do.

For someone to use AI to respond in their own forum post shows a lot about a person and inherently the work they produce.

Lets leave it at that.

1 Like

A bunch of most likely Google monkeys on their high horse passing judgment on other people who use othe r tools to solve problems. The whole argument is silly. What do you have to offer and who are you to pass judgment on people? Do you think you can write better code faster than AI? Why do you assume that just because someone is using AI it mist be junk.

These are the arguments I remember from the 90s and the advent of search engines and people didn’t trust them.

I suggest you get off your high horse and get with the program because AI isn’t going anywhere and give the poor guy a break and stop piling on him.

1 Like