move allow_dns_query into hiera