It's quite literally how I laid it out. I have a Fedora server with an Unbound container for roothints lookup, and a pihole container for internal DNS sevices. It's taken a lot of time to get working like any homelab stuff.
I've never heard of powerDNS but you may be in a situation where you need to read their docs or try and find other posts or videos of what you're trying to accomplish. Sorry I wasn't much more help.
Kei was recently found to botch all of their safety test scores for many years. As another commenter said, any crash in that design is guaranteed life threatening without some type of buffer.