Skip to content

SYSTEM Cited by 4 sources

Big Pineapple

Big Pineapple is Cloudflare's in-house recursive DNS resolver. It is the software that powers systems/cloudflare-1-1-1-1-resolver|1.1.1.1, 1.1.1.1 for Families, Gateway DNS, and DNS Firewall — i.e. every public resolver surface Cloudflare operates. Disclosed by name in the 2026-05-06 DNSSEC .de outage post and introduced publicly in the earlier Big Pineapple intro post (not yet ingested on this wiki).

From the 2026-05-06 post:

"For 1.1.1.1 we have our own resolver referred to as Big Pineapple, which also powers 1.1.1.1 for Families, Gateway DNS, DNS Firewall, and more."

Role in Cloudflare's DNS stack

Big Pineapple sits at the recursive-resolver layer — the piece that takes a client's DNS query, walks the DNS hierarchy from root → TLD → authoritative nameserver, validates DNSSEC signatures, and caches answers. It is distinct from Cloudflare's authoritative DNS (which serves records for customer zones) and distinct from the internal origin resolver Cloudflare's CDN uses for customer origin-name resolution — though during the 2026-05-05 .de incident, both the Big-Pineapple-backed 1.1.1.1 and the internal origin resolver received similar NTA-equivalent mitigations.

Implementation details disclosed

From the 2026-05-06 DNSSEC incident:

  • No native NTA mechanism at the time of the incident. Cloudflare had to use "an existing override rule mechanism to mark .de as an insecure zone, which causes all .de queries to be resolved as if they don't have DNSSEC enabled. This is functionality equivalent to an NTA, though it is not formally defined in any RFC." Implied future work: implement a proper RFC-7646 NTA mechanism.
  • Serve-stale is implemented per RFC 8767. During the .de outage this significantly cushioned user impact — NOERROR rates stayed stable for hours despite upstream SERVFAILs, because expired-TTL records were still being served from cache.
  • Extended DNS Error (EDE) code propagation had a latent bug. The trust-chain verifier correctly detected DNSSEC-Bogus signatures and created an EDE 6 code, but the outer resolver layer discarded it and emitted EDE 22 ("No Reachable Authority") instead. The bug was disclosed in the 2026-05-06 post with a commitment to fix: "We're aware that this isn't helpful for 1.1.1.1 users and will be fixing our responses to surface the DNSSEC errors."

The DNS cache and its memory footprint

Big Pineapple stores over 250 billion DNS cache entries across Cloudflare's fleet at any moment — so per-entry memory is a fleet-scale lever: a single wasted byte per entry costs >250 GB of RAM. Each item is a CacheKey (qname, qtype, authenticated, tag) → CacheEntry (the answer/authority/additional record sections plus metadata: timestamp, inception, ttl, hits, extended errors). Entries are immutable after insert, and ECS-heavy POPs cache many versions of the same query (one per client network), multiplying entry count and per-entry memory.

The 2026-08-27 DNS-cache memory-optimization post disclosed five successive Rust struct-layout changes to CacheEntry/Record that cut the per-entry footprint 56% (953 → 420 bytes) and freed ~100 TB fleetwide (≈130 Gen 13 servers), while making the cache faster (insert throughput +43%, lookup latency −19%):

  1. Vec/String → Box<[T]>/Box<str> on the immutable entry — drops the capacity field + growth slack; 64 B/entry, >15 TB fleetwide. (box-slice-over-vec-for-immutable-data)
  2. Three record-section lists → one list + two u16 offsets — records fit in a u16; 28 B/entry. Booleans packed into a bitflag also trimmed padding. (single-buffer-with-section-offsets)
  3. owner: Option<Box<Name>> — None reconstructs the queried domain from the cache key at read time; most records need no owner allocation. (infer-field-from-context-key)
  4. Box the large RecordData enum variants — the enum was sized to NAPTR (144 B) but A (4 B) + AAAA (16 B) are >80% of traffic; boxing rare large variants saves 120 B/record. (box-large-enum-variants)
  5. Records stored as one contiguous Box<[u8]> in wire format — eliminates per-variant jemalloc size-class rounding + restores locality; A/AAAA/TXT/DNSSEC types memcpy straight into responses (−5% lookup latency). Built via a reusable scratchspace buffer (+13% insert throughput). (records-in-wire-format-in-cache)

Big Pineapple is written in Rust and uses jemalloc as its allocator; the post is the wiki's canonical instance of DNS-cache memory engineering and the first to name jemalloc as Big Pineapple's allocator.

Known incidents affecting Big Pineapple (via 1.1.1.1)

Big Pineapple is the software whose bugs + configuration changes show up in the 1.1.1.1 incident record. See systems/cloudflare-1-1-1-1-resolver for the full list. The two most-recent failure modes:

Seen in

  • sources/2026-05-06-cloudflare-when-dnssec-goes-wrong-de-tld-outage — first canonical wiki naming of Big Pineapple as the software behind 1.1.1.1. Disclosed as the substrate that absorbed the .de DNSSEC break via serve-stale + override-rule NTA-equivalent. Self-disclosed the EDE-propagation bug.
  • sources/2026-07-14-cloudflare-dnssec-nta-ede-33 — second wiki instance. Big Pineapple now implements EDE 33 (Negative Trust Anchor) per draft-farrokhi-dnsop-ede-nta, closing the NTA transparency gap. EDE-propagation bug from the .DE incident confirmed fixed (EDE 9 correctly surfaces alongside EDE 33 during the .AL incident).
  • sources/2026-08-27-cloudflare-how-we-saved-100-terabytes-of-memory-by-optimizing-1111s-dns — DNS-cache memory engineering. Five Rust struct-layout optimizations on CacheEntry/Record cut per-entry footprint 56% (953→420 B) and freed ~100 TB fleetwide while making the cache faster. First wiki instance naming jemalloc as Big Pineapple's allocator and disclosing the 250-billion-entry cache scale.
  • sources/2026-09-10-cloudflare-1111-post-quantum-dnssec — Big Pineapple now validates ML-DSA-44 DNSSEC signatures (algorithm number 18), the resolver-side of post-quantum DNSSEC. Also the source of the Big-Pineapple-wide transport mix (~60% of queries over UDP across all Big Pineapple services vs ~85% for 1.1.1.1 specifically). The 2,420-byte ML-DSA-44 signatures force truncation → TCP fallback the resolver already handles routinely.
Last updated · 766 distilled / 2,225 read