ADR 0194: the no-copies check allows each node's loopback stub

This commit is contained in:
2026-10-03 21:51:03 +02:00
parent 6b6ff76a19
commit 13e28e6873
2 changed files with 8 additions and 7 deletions
@@ -133,8 +133,9 @@ as a LAN's DNS server is pointed elsewhere before that node stops answering.
- **Asking:** on each node, `resolvectl` shows the tunnel's link with `mesh-resolver` and the suffix as
its routing domain; a name under `.internal` is answered by it, and a public name is answered
without it (its query log shows no public name from a node).
- **No copies:** no node but the holder listens on port 53, and no node's `/etc/hosts` carries a mesh
region.
- **No copies:** no node but the holder answers DNS on a private or LAN address — every other node's
port 53 is systemd-resolved's loopback stub and nothing else — and no node's `/etc/hosts` carries a
mesh region.
- **A LAN:** the router's DHCP DNS option names no node's address.
## References