diff --git a/docs/reference/cli/boundary.md b/docs/reference/cli/boundary.md
index 0c99605d8d..9b18c8a493 100644
--- a/docs/reference/cli/boundary.md
+++ b/docs/reference/cli/boundary.md
@@ -97,16 +97,6 @@ Enable pprof profiling server.
Set port for pprof profiling server.
-### --configure-dns-for-local-stub-resolver
-
-| | |
-|-------------|--------------------------------------------------------------|
-| Type | bool |
-| Environment | $BOUNDARY_CONFIGURE_DNS_FOR_LOCAL_STUB_RESOLVER |
-| YAML | configure_dns_for_local_stub_resolver |
-
-Configure DNS for local stub resolver (e.g., systemd-resolved). Only needed when /etc/resolv.conf contains nameserver 127.0.0.53.
-
### --jail-type
| | |
@@ -118,6 +108,16 @@ Configure DNS for local stub resolver (e.g., systemd-resolved). Only needed when
Jail type to use for network isolation. Options: nsjail (default), landjail.
+### --use-real-dns
+
+| | |
+|-------------|-------------------------------------|
+| Type | bool |
+| Environment | $BOUNDARY_USE_REAL_DNS |
+| YAML | use_real_dns |
+
+Use real DNS in the jail instead of the dummy DNS (allows DNS exfiltration). Default: false.
+
### --disable-audit-logs
| | |
diff --git a/enterprise/cli/testdata/coder_boundary_--help.golden b/enterprise/cli/testdata/coder_boundary_--help.golden
index f3c8c87f34..257981b3fe 100644
--- a/enterprise/cli/testdata/coder_boundary_--help.golden
+++ b/enterprise/cli/testdata/coder_boundary_--help.golden
@@ -20,10 +20,6 @@ OPTIONS:
--config yaml-config-path, $BOUNDARY_CONFIG
Path to YAML config file.
- --configure-dns-for-local-stub-resolver bool, $BOUNDARY_CONFIGURE_DNS_FOR_LOCAL_STUB_RESOLVER
- Configure DNS for local stub resolver (e.g., systemd-resolved). Only
- needed when /etc/resolv.conf contains nameserver 127.0.0.53.
-
--disable-audit-logs bool, $DISABLE_AUDIT_LOGS
Disable sending of audit logs to the workspace agent when set to true.
@@ -50,6 +46,10 @@ OPTIONS:
--proxy-port int, $PROXY_PORT (default: 8080)
Set a port for HTTP proxy.
+ --use-real-dns bool, $BOUNDARY_USE_REAL_DNS
+ Use real DNS in the jail instead of the dummy DNS (allows DNS
+ exfiltration). Default: false.
+
--version bool
Print version information and exit.
diff --git a/go.mod b/go.mod
index 85778ffc4e..fe58d30fcd 100644
--- a/go.mod
+++ b/go.mod
@@ -361,7 +361,7 @@ require (
github.com/mdlayher/sdnotify v1.0.0 // indirect
github.com/mdlayher/socket v0.5.0 // indirect
github.com/microcosm-cc/bluemonday v1.0.27
- github.com/miekg/dns v1.1.58 // indirect
+ github.com/miekg/dns v1.1.72 // indirect
github.com/mitchellh/copystructure v1.2.0 // indirect
github.com/mitchellh/go-homedir v1.1.0 // indirect
github.com/mitchellh/go-ps v1.0.0 // indirect
@@ -475,7 +475,7 @@ require (
github.com/coder/agentapi-sdk-go v0.0.0-20250505131810-560d1d88d225
github.com/coder/aibridge v1.0.2
github.com/coder/aisdk-go v0.0.9
- github.com/coder/boundary v0.6.1
+ github.com/coder/boundary v0.8.0
github.com/coder/preview v1.0.4
github.com/danieljoos/wincred v1.2.3
github.com/dgraph-io/ristretto/v2 v2.4.0
diff --git a/go.sum b/go.sum
index 96a9091a49..7c99df82eb 100644
--- a/go.sum
+++ b/go.sum
@@ -931,8 +931,8 @@ github.com/coder/aibridge v1.0.2 h1:cVPr9+TFLIzULpKPGI/1lnL14+DruedR7KnjZHklIEU=
github.com/coder/aibridge v1.0.2/go.mod h1:c7Of2xfAksZUrPWN180Eh60fiKgzs7dyOjniTjft6AE=
github.com/coder/aisdk-go v0.0.9 h1:Vzo/k2qwVGLTR10ESDeP2Ecek1SdPfZlEjtTfMveiVo=
github.com/coder/aisdk-go v0.0.9/go.mod h1:KF6/Vkono0FJJOtWtveh5j7yfNrSctVTpwgweYWSp5M=
-github.com/coder/boundary v0.6.1 h1:hLnrincIFA8Wak5SrH/xQDIIhkKQpnHVotLwC585z7g=
-github.com/coder/boundary v0.6.1/go.mod h1:jEXVbTGQP9JFoXkyzsnitj2rsWJuTt+VVej1Yzr2CkQ=
+github.com/coder/boundary v0.8.0 h1:g/H6VIGY4IoWeKkbvao7zhO1BAQe7upSHfHzoAZxdik=
+github.com/coder/boundary v0.8.0/go.mod h1:7LXg454okcxIQm08GouuvoWjH1uGkHdbEXiPbZgzcQk=
github.com/coder/bubbletea v1.2.2-0.20241212190825-007a1cdb2c41 h1:SBN/DA63+ZHwuWwPHPYoCZ/KLAjHv5g4h2MS4f2/MTI=
github.com/coder/bubbletea v1.2.2-0.20241212190825-007a1cdb2c41/go.mod h1:I9ULxr64UaOSUv7hcb3nX4kowodJCVS7vt7VVJk/kW4=
github.com/coder/clistat v1.2.0 h1:37KJKqiCllJsRvWqTHf3qiLIXX0JB6oqE5oxcqgdLkY=
@@ -1604,8 +1604,8 @@ github.com/mdlayher/socket v0.5.0 h1:ilICZmJcQz70vrWVes1MFera4jGiWNocSkykwwoy3XI
github.com/mdlayher/socket v0.5.0/go.mod h1:WkcBFfvyG8QENs5+hfQPl1X6Jpd2yeLIYgrGFmJiJxI=
github.com/microcosm-cc/bluemonday v1.0.27 h1:MpEUotklkwCSLeH+Qdx1VJgNqLlpY2KXwXFM08ygZfk=
github.com/microcosm-cc/bluemonday v1.0.27/go.mod h1:jFi9vgW+H7c3V0lb6nR74Ib/DIB5OBs92Dimizgw2cA=
-github.com/miekg/dns v1.1.58 h1:ca2Hdkz+cDg/7eNF6V56jjzuZ4aCAE+DbVkILdQWG/4=
-github.com/miekg/dns v1.1.58/go.mod h1:Ypv+3b/KadlvW9vJfXOTf300O4UqaHFzFCuHz+rPkBY=
+github.com/miekg/dns v1.1.72 h1:vhmr+TF2A3tuoGNkLDFK9zi36F2LS+hKTRW0Uf8kbzI=
+github.com/miekg/dns v1.1.72/go.mod h1:+EuEPhdHOsfk6Wk5TT2CzssZdqkmFhf8r+aVyDEToIs=
github.com/minio/asm2plan9s v0.0.0-20200509001527-cdd76441f9d8/go.mod h1:mC1jAcsrzbxHt8iiaC+zU4b1ylILSosueou12R++wfY=
github.com/minio/c2goasm v0.0.0-20190812172519-36a3d3bbc4f3/go.mod h1:RagcQ7I8IeTMnF8JTXieKnO4Z6JCsikNEzj0DwauVzE=
github.com/mitchellh/copystructure v1.2.0 h1:vpKXTN4ewci03Vljg/q9QvCGUDttBOGBIa15WveJJGw=