Reading track

DNS, DHCP and IPAM
you actually control.

SpatiumDDI puts real BIND9, PowerDNS, Technitium and Kea under one control plane, on hardware you own. It’s Apache 2.0 end to end: every feature is free, and your zone data never leaves your network.

SpatiumDDI is open-source DDI with flat-rate support instead of a six-figure, per-IP licence. The price is on this page — no sales call needed.

Try it in minutes: boot the ISO, docker compose up, or helm install. No licence keys, no registration — and run as many copies as you like.

API-first — everything in the UI is an API call · appliance ISO with A/B rollback · multi-cloud DNS

Early Adopter Program: a fixed-fee pilot beside your incumbent, credited in full toward your contract — 3 slots →

BIND9 · PowerDNS · Technitium · Kea Real engines, not reimplementations
Everything is an API call One /api/v1 behind every click — OpenAPI published with each release
Appliance ISO HTTPS in minutes — one node to a 3/5/7-node HA cluster
Tamper-evident audit SHA-256 hash chain, append-only
Zero telemetry No analytics, no crash reports — enforced by CI
The stack

It doesn't configure your DDI — it runs it

BIND9, PowerDNS, Technitium and Kea ship as first-class service containers the control plane owns. Config changes converge in under a second over a long-poll-plus-wake channel — and every agent caches its last-known-good config on local disk, so your network keeps resolving even when the control plane doesn’t.

SpatiumDDI control plane Apache 2.0 Web UI — React REST API · every UI action Celery workers IPAM · PostgreSQL 16 — source of truth Redis 7 — wake bus SHA-256 hash-chained audit · zero telemetry, enforced by CI Agentless drivers Windows DNS & DHCP WinRM — agentless Technitium API · FortiGate DHCP Cloudflare · Route 53 · Azure Google · DigitalOcean · Hetzner Linode · Vultr drift reports — read-only Read-only mirrors → feed IPAM never write back K8s · Docker · Proxmox VE Tailscale · NetBird · UniFi OPNsense · AWS · Azure · GCP PAN-OS · FortiGate · Meraki one deliberate write path: block sync — gated, audited, off by default DNS service containers BIND9 PowerDNS Technitium DNSSEC · views · RPZ · catalog zones DoT · DoH · DoQ · GeoDNS steering DHCP Kea HA pair — load-balanced or hot-standby fingerprints · PXE / iPXE owns · configures · upgrades long-poll + Redis wake — converges in < 1 s last-known-good config cached on disk Fail-open: agents keep serving from cached config even when the control plane is down. Your network — laptops · servers · Wi-Fi · IoT · VMs
One control plane, real engines under it — sub-second convergence, and a fail-open design: resolution never depends on the manager being up.
The platform

One source of truth, three surfaces

IPAM tree, DNS zones, DHCP scopes — one UI, one REST API. Hostname changes in IPAM propagate to DNS; reservations propagate to DHCP. Everything below ships today, free, under Apache 2.0.

Hierarchical IPAM

Spaces, blocks and subnets with full IPv4 and IPv6 — EUI-64, random or sequential allocation. Split, merge, resize, find-free, plus a CIDR planner that previews before it commits.

DNS you actually run

BIND9, PowerDNS or Technitium per server group, auto-registering. DNSSEC and catalog zones on all three, DoT and DoH listeners with encrypted upstream forwarding — plus split-horizon views and RPZ on BIND9, ALIAS and LUA on PowerDNS, DNS-over-QUIC on Technitium.

DHCP with real HA

Kea with group-centric high availability — load-balanced or hot-standby, with self-healing peer drift. DHCPv6, prefix delegation, PXE/iPXE boot profiles, a 95-entry option library — and fingerprint-driven device policies that compile a device class into a real Kea client class.

Agentless Windows & cloud

Point it at existing Windows DCs over WinRM — nothing installed on the Windows side — or at a Technitium server you already run. Eight cloud DNS providers ship as drivers: Cloudflare, Route 53, Azure, Google Cloud, DigitalOcean, Hetzner, Linode and Vultr.

Ships as an OS appliance

Boot one ISO, answer a few prompts, and you're on HTTPS with the full stack in minutes. Atomic A/B upgrades, health-gated rollback — and one appliance grows into a 3, 5 or 7-node HA cluster from the fleet tab, with replicated Postgres and a floating VIP.

Built for delegation

Group-based RBAC with LDAP, OIDC, SAML, RADIUS and TACACS+, resource-scoped API tokens and two-person approval workflows. Hand a subnet or a zone to a department without handing over root — every mutation lands in a SHA-256 hash-chained, append-only audit log.

Security analytics, built in

Tunneling, DGA and C2-beaconing detection over the query logs you already collect, RPZ blocklists from a curated 19-source catalog, BGP prefix-hijack detection with RPKI validation via a receive-only looking-glass collector. All optional, all on your hardware.

Automation without a moat

One /api/v1 for everything, with the OpenAPI schema published with every release. Typed webhook events for anything that changes, HMAC-signed with retries and a dead-letter queue — plus an MCP endpoint so an AI operator can drive it, every write gated behind an explicit apply.

For Windows shops

Already on Windows DNS and DHCP? Start there.

Nothing to install on the DC

Point SpatiumDDI at your domain controllers — RFC 2136 for records, WinRM for zones and scopes, a service account, ports 53 and 5985/5986. No agent. Every DC’s zones, records and scopes land in one IPAM tree, live DHCP leases mirror in near real time, and a per-zone drift report shows what someone changed by hand on the server.

Manage in place, migrate when you choose — or never

Windows DNS is managed from the same console as everything else, with the DCs staying exactly where they are. If you later want off: the importers pull the live estate with preview-before-commit, the parallel run proves parity, and the cutover moves one zone or scope at a time with rollback and a lease handover — Windows stays warm behind it. If you never do, you still have the visibility.

Three ways to run it

Boot one ISO, keep a fleet — or bring your own cluster

The appliance is Debian 13 with embedded k3s: HTTPS in 2–5 minutes, no Docker or Kubernetes to set up, and a headless preseed install for fleets. Upgrades write to the inactive slot and only a healthy boot keeps them; one node grows into a 3, 5 or 7-node HA cluster without reinstalling. Already run Kubernetes or Docker? The same containers ship as a Helm chart and a Compose file.

Appliance node — two root slots Slot A — running current release, serving Slot B — new image staged while A serves separate state partition — config survives upgrades reboot Health gate checks on boot Boot from B upgrade done Stay on A automatic rollback healthy not healthy Fleet — 3/5/7-node HA clusters rolling upgrades, node by node · database switchover · air-gap mirror supported measured sizing (250K records · 20K devices): 4 vCPU · 8 GiB recommended — floor 3 vCPU · 6 GiB
Upgrades are atomic: the new image lands in the inactive slot, and only a healthy boot gets to keep it. The same machinery rolls a whole cluster, one node at a time.

Debian 13 + embedded k3s. HTTPS in 2–5 minutes.

1. Download the ISO from the releases page
2. Boot it on a VM or bare metal
3. Answer the installer wizard
4. Browse to https://<your-ip>

Any host with Docker — the quickest way to a lab.

git clone https://github.com/spatiumnorth/spatiumddi
cd spatiumddi
cp .env.example .env   # set POSTGRES_PASSWORD + SECRET_KEY
make build
make migrate
make up

Already run a cluster? One umbrella chart, published as OCI.

# pick the chart version from the releases page
helm install ddi \
  oci://ghcr.io/spatiumnorth/charts/spatiumddi \
  --version <chart-version> \
  --namespace spatiumddi --create-namespace

Default login is admin / admin, and it forces a password change on first use. Full walkthrough in Getting Started.

How it lands

Prove it on your network, not ours

Most evaluations stall on "we can’t put production on something new yet." So nothing touches production: the evaluation runs beside it, and has to prove parity before it earns authority.

Run it free

ISO, Docker Compose or Helm. The full platform, every feature, no licence — in as many labs, test benches and DR rehearsals as you want.

Import your real config

BIND9 archives, Windows DNS & DHCP, PowerDNS and Technitium REST, Kea and ISC dhcpd configs, cloud zones, NetBox. Preview-before-commit, re-runnable, read-only against the source — and each object commits alone, so one bad row never rolls back the rest.

Prove it answers identically

A parity diff against what your servers answer right now — every difference classified by why the two sides differ — plus a shadow replay of real queries sampled from the query log, sent to both systems with recursion off so a cached answer can’t stand in.

Cut over one zone at a time

Sixteen readiness checks first — the hard ones can never be forced. Then TTL preflight with exact undo, DHCP lease handover so clients keep their addresses, per-zone and per-scope switches that each carry their own rollback and recovery estimate, and a generated operator runbook. The old server stays warm.

Your incumbent — still authoritative, untouched 1 Import read-only · re-runnablepreview → commitprovenance-stamped 2 Parity diff live answers, both sidesevery differenceclassified by cause 3 Shadow replay real queries, sampledrecursion off —the cache can’t answer 4 Cut over, per item 16 readiness checksTTL preflight · lease handoverrunbook generated old zone retired new zone authoritative SpatiumDDI — running beside, nothing dispatched zero writes to your servers reversible in minutes per-item rollback · recovery estimate in seconds
Import fidelity first, then answer parity on your real traffic — and only then does authority move, one zone or scope at a time. The guided cutover ships for Windows DNS & DHCP estates today.

We import your actual configuration, stand up beside you without touching anything you own, replay your real queries at both systems, and show you the diff. Then you cut over one zone, keep the old one warm — and roll back in minutes if you don’t like it. The guided cutover ships for Windows DNS & DHCP estates today; the importers cover BIND9, PowerDNS, Technitium, Kea, ISC dhcpd, cloud zones and NetBox.

The project

Help us make it better

The platform is Apache 2.0 — the whole thing, in the open. That is worth more when people outside this company shape it. Here is what genuinely helps, roughly in order of how much.

Tell us what broke

A report with the shape of your config, the query you sent and the answer you expected is worth more than a feature request. Issues are public, and so are the replies.

Send a config we choke on

The importers are only as good as the real-world files they have met. A sanitised BIND9 zone, Kea lease file or Windows DNS export that we parse wrongly is among the most useful things you can hand us.

Write the code

Drivers, importers, tests, packaging. The repository takes pull requests from anyone — there is no contributor tier, and no part of the tree is held back for a paid edition.

Fix the documentation

If a page led you the wrong way, that is a defect like any other. Documentation changes are reviewed on the same footing as code.

You do not need a support plan to file an issue, and contributing does not require one either. The paid relationship is about response times, not access.

A native iOS app is being built in the open too — read-mostly, against the same API, for checking the estate from your pocket. iOS first; Android is a maybe. SpatiumDDI Mobile on GitHub →

Open an issue Browse the source

The economics

You're already paying for DDI —
and you're paying too much.

Every network already does DNS, DHCP and address management. There are only two ways to pay for it today, and both are the expensive way.

Paying a vendor

  • Per-IP metering at US $5–7.70 per address, per year — the bill grows every time the network does.
  • Quote-only pricing you can't evaluate without a sales call.
  • A sealed appliance wrapped around the same open-source engines you could run yourself.

Doing it by hand

  • Provisioning a new segment takes days of manual edits instead of minutes.
  • Hand-managed zones and spreadsheets eat ~40 staff-hours a month in troubleshooting.
  • Audit evidence gets assembled manually, for weeks, every cycle.

SpatiumDDI removes both. The software is free and open source. The assurance around it is flat-rate, banded by deployment size, and published below — no meter, no quote call.

Commercial incumbent SpatiumDDI + support Commercial incumbent, Year 1: ~C$351K C$351K SpatiumDDI + support, Year 1: ~C$77K C$77K −78% Year 1 (incl. implementation) Commercial incumbent, ongoing: ~C$194K/yr C$194K SpatiumDDI + support, ongoing: ~C$52K/yr C$52K −73% Ongoing, per year
Illustrative annual cost, CAD — a Medium-band university (~16K addresses, 3 sites). Conservative: the commercial column uses the lowest published incumbent tiers.
Illustrative: mid-size university (~16K addresses, 3 sites) Commercial DDI SpatiumDDI + support Saving
Year 1, including implementation ~C$351K ~C$77K ~78%
Ongoing, per year ~C$194K ~C$52K ~73%
Time returned

What unified DDI gives back

The savings don't come from us — they come from unifying and automating DDI, which the platform does without the per-address licence.

~70% less staff time spent on DDI once it is unified and automated
5 days → 15 min to provision a new machine or segment
~40 h/mo → ~0 spreadsheet-driven troubleshooting eliminated
~80% less audit-prep effort — evidence collects itself

Figures from the incumbents' own commissioned customer studies (Forrester TEI 2023 and vendor case studies) — cited as such, because the lever is the same whoever sells it.

Adoption

De-risked by design

Nothing you run is touched during evaluation: your configuration is imported read-only, the proof is a diff of real answers from both systems, and authority moves one zone at a time — with the old server kept warm.

1 · Run it free $0 — full platform ISO · Compose · Helm 2 · Run it beside your config, imported read-only — nothing sent to your servers 3 · Prove parity real queries replayed at both systems — answers diffed 4 · Cut over one zone at a time old server kept warm zero production risk zero production risk zero production risk rollback in minutes
Standing it up is decoupled from giving it authority: nothing changes in production until the parity and shadow-replay reports say both systems answer identically.
For Windows shops

Already on Windows DNS and DHCP? Start there.

Central visibility over what you already run

Plenty of networks do DNS and DHCP on their domain controllers because that is what came with Windows — and nobody has one view across all of them. SpatiumDDI connects to every DC directly, with nothing installed, and puts it all in one place: every zone, every scope, every live lease, and a report of what has drifted. No forklift, no per-IP licence.

Migrate on your schedule — or don’t

Keep Windows as the engine and manage it from SpatiumDDI, indefinitely. If you decide to move to the bundled engines, the same parallel-run path applies, one zone at a time, with the old server kept warm. Either way the evaluation costs nothing, and the visibility arrives on day one.

Assurance

The questions your risk register will ask

No lock-in, by construction

The platform is Apache 2.0. If Spatium North disappeared tomorrow, you’d still have a working system and all of its source code. That isn’t something a proprietary vendor can offer you.

A price you can read

Flat yearly rates, published on this site and banded by deployment size — never by IP count. Education and public sector get 15% off support plans and training. And the software itself is free everywhere you run it: production, lab, staging, DR. No per-instance licence, no lab fee.

Backed by the people who build it

Support comes from the founders who write the product, in Montréal — which also ticks the Canadian-vendor and data-sovereignty boxes. Every enquiry gets a founder reply within one business day.

Why this exists

DDI has been locked up for twenty years: six-figure licences, sealed appliances and quote-only pricing, all wrapped around open-source engines. We think it deserves a proper open-source home. SpatiumDDI makes DDI accessible: the full platform, Apache 2.0, on hardware you own — with the price of support written down, not quoted.

Buy the response, not the features

Support pricing, published

The software is $0 forever, everywhere you run it — production, lab or test bench. A support plan buys response: someone on the hook, at a flat yearly rate you can read off this grid. Bands follow deployment size (locations and server nodes), never an IP count.

Small 1 site Medium 2–4 sites Large 5+ sites
Essential Business hours, next-business-day response Open to early adopters — sign up today $15,000$22,000$30,000
Standard Same-business-day response Opens ~Q3 2027 (our estimate) — join the waitlist $45,000$65,000$90,000
Premium 24×7 critical-response path By arrangement — starts with a call $70,000$95,000$120,000

Add-on

24×7 severity-1 path+$15,000a year, added to any Standard plan, in every bandWaitlist — est. Q3 2027

An add-on to Standard, not a fourth plan: a 24×7 path that pages our on-call, for severity 1 only — DNS or DHCP down for a site or a campus. Everything else stays Standard: same-business-day response, named contact, quarterly reviews. It isn’t Premium: no HA architecture review, no roadmap input.

  • All prices CAD per year.
  • Education & public sector: 15% off support plans and training.
  • Support renewals follow Canadian CPI — floor 3%, cap 6%.
  • Beyond Large (national, multi-region estates): custom-scoped.
  • No per-IP metering — your band moves when you open a campus, not when you add a printer.

Paid Discovery & Architecture

$3–5K fixed

Two weeks. An architecture document for your estate plus a fixed-price deployment quote. Fee credits toward deployment.

Quick-start deployment

$8K

Guided single-site production setup, from ISO to acceptance.

White-glove migration

from ~$25K

Full incumbent migration: import, parallel run, parity proof, staged cutover, acceptance.

Bespoke development

$1,800/day

Anything the fixed-price catalogue does not cover.

Band definitions, plan details and FAQ →

Managed service provider? Partner pricing has its own page →

Pilots

Early Adopter Program

$5K fixed, 60–90 days, run as a parallel deployment beside your incumbent: your real config imported, nothing dispatched to your servers, and a parity / shadow-replay report at the end showing whether SpatiumDDI answers identically to what you run today. Success criteria agreed up front — and the fee credits in full against your contract. Limited to 3 concurrent pilots; that's a capacity fact, not a marketing device.

Tell us about your network

Essential support is open to early adopters, Standard has a waitlist, and the Early Adopter Program pilots are running. Everything except email is optional — the estate questions map straight onto the pricing bands, so you get a real number back, not a call script.

Your estate (optional — this maps to the pricing bands)

A founder replies within one business day. No newsletter, no drip campaign.
We use what you send only to reply to you — privacy notice.