From 13e28e6873d4ab7e3221cc6118173e805d467953 Mon Sep 17 00:00:00 2001 From: jochen Date: Sat, 3 Oct 2026 21:51:03 +0200 Subject: [PATCH] ADR 0194: the no-copies check allows each node's loopback stub --- ...olver-and-every-node-asks-it-for-the-meshs-names.md | 5 +++-- 03-DESIGN/01-to-be/08-connectivity.md | 10 +++++----- 2 files changed, 8 insertions(+), 7 deletions(-) diff --git a/02-DECISIONS/0194-the-mesh-has-one-resolver-and-every-node-asks-it-for-the-meshs-names.md b/02-DECISIONS/0194-the-mesh-has-one-resolver-and-every-node-asks-it-for-the-meshs-names.md index 85da883..08c5935 100644 --- a/02-DECISIONS/0194-the-mesh-has-one-resolver-and-every-node-asks-it-for-the-meshs-names.md +++ b/02-DECISIONS/0194-the-mesh-has-one-resolver-and-every-node-asks-it-for-the-meshs-names.md @@ -133,8 +133,9 @@ as a LAN's DNS server is pointed elsewhere before that node stops answering. - **Asking:** on each node, `resolvectl` shows the tunnel's link with `mesh-resolver` and the suffix as its routing domain; a name under `.internal` is answered by it, and a public name is answered without it (its query log shows no public name from a node). -- **No copies:** no node but the holder listens on port 53, and no node's `/etc/hosts` carries a mesh - region. +- **No copies:** no node but the holder answers DNS on a private or LAN address — every other node's + port 53 is systemd-resolved's loopback stub and nothing else — and no node's `/etc/hosts` carries a + mesh region. - **A LAN:** the router's DHCP DNS option names no node's address. ## References diff --git a/03-DESIGN/01-to-be/08-connectivity.md b/03-DESIGN/01-to-be/08-connectivity.md index eb06271..8249359 100644 --- a/03-DESIGN/01-to-be/08-connectivity.md +++ b/03-DESIGN/01-to-be/08-connectivity.md @@ -358,10 +358,10 @@ seat of capacity one, placed on the node every tunnel converges on. It holds one `.internal` and everything under it — and listens on the private network only. Every node's `node-resolver-config` routes the mesh's suffix to it and leaves every other name with public resolvers; plain `resolv.conf` cannot route by domain, so the asking side is a stub that can — a -`systemd-resolved` module claiming `node-resolver-config` in place of `resolv-conf`, routing the suffix -to `mesh-resolver`. The container runtime -cannot use a loopback stub, so its `dns` names `mesh-resolver`, which forwards public names for -containers — the one place a public name passes through the mesh +`systemd-resolved` module claiming `node-resolver-config` in place of `resolv-conf`, routing the +suffix to `mesh-resolver`. The container runtime cannot use a loopback stub, so its `dns` names +`mesh-resolver`, which forwards public names for containers — the one place a public name passes +through the mesh ([ADR 0194](../../02-DECISIONS/0194-the-mesh-has-one-resolver-and-every-node-asks-it-for-the-meshs-names.md)). **No node holds a copy.** The per-node resolver, its zones file and the mesh's region of `/etc/hosts` @@ -369,7 +369,7 @@ go: every resolution fault found on 2026-10-03 was a copy disagreeing with the t read once at start, an operator's old line beside the mesh's, a node's resolver lent to a LAN. No member's resolver answers a LAN; a router pointing at one is moved first. *Checked by `resolvectl` on each node (the tunnel's link, `mesh-resolver`, the suffix as routing domain), by no node but the -holder listening on port 53, and by the router's DHCP DNS option naming no node.* +holder answering DNS on a private or LAN address, and by the router's DHCP DNS option naming no node.* *What follows describes the per-node resolver this replaces — how it was built and why the roles were split. The split stands; the serving role's scope is what moved.*