I integrated an unbound instance as the DNS resolver of my homegrown CGNAT gateway yesterday. Hooked it up to the main (userland) routing process with a pair of veth devices so that all of the DNS-related networking went out the same path as the rest of the customer IP traffic and never touched the host network stack.
This worked great, except… only with some authoritative servers! The root servers worked fine, as did .com TLD, example.com resolved great… but things like google.com didn’t.