ADR 0194: the no-copies check allows each node's loopback stub

This commit is contained in:
2026-10-03 21:51:03 +02:00
parent 6b6ff76a19
commit 13e28e6873
2 changed files with 8 additions and 7 deletions
@@ -133,8 +133,9 @@ as a LAN's DNS server is pointed elsewhere before that node stops answering.
- **Asking:** on each node, `resolvectl` shows the tunnel's link with `mesh-resolver` and the suffix as - **Asking:** on each node, `resolvectl` shows the tunnel's link with `mesh-resolver` and the suffix as
its routing domain; a name under `.internal` is answered by it, and a public name is answered its routing domain; a name under `.internal` is answered by it, and a public name is answered
without it (its query log shows no public name from a node). without it (its query log shows no public name from a node).
- **No copies:** no node but the holder listens on port 53, and no node's `/etc/hosts` carries a mesh - **No copies:** no node but the holder answers DNS on a private or LAN address — every other node's
region. port 53 is systemd-resolved's loopback stub and nothing else — and no node's `/etc/hosts` carries a
mesh region.
- **A LAN:** the router's DHCP DNS option names no node's address. - **A LAN:** the router's DHCP DNS option names no node's address.
## References ## References
+5 -5
View File
@@ -358,10 +358,10 @@ seat of capacity one, placed on the node every tunnel converges on. It holds one
`<node>.internal` and everything under it — and listens on the private network only. Every node's `<node>.internal` and everything under it — and listens on the private network only. Every node's
`node-resolver-config` routes the mesh's suffix to it and leaves every other name with public `node-resolver-config` routes the mesh's suffix to it and leaves every other name with public
resolvers; plain `resolv.conf` cannot route by domain, so the asking side is a stub that can — a resolvers; plain `resolv.conf` cannot route by domain, so the asking side is a stub that can — a
`systemd-resolved` module claiming `node-resolver-config` in place of `resolv-conf`, routing the suffix `systemd-resolved` module claiming `node-resolver-config` in place of `resolv-conf`, routing the
to `mesh-resolver`. The container runtime suffix to `mesh-resolver`. The container runtime cannot use a loopback stub, so its `dns` names
cannot use a loopback stub, so its `dns` names `mesh-resolver`, which forwards public names for `mesh-resolver`, which forwards public names for containers — the one place a public name passes
containers — the one place a public name passes through the mesh through the mesh
([ADR 0194](../../02-DECISIONS/0194-the-mesh-has-one-resolver-and-every-node-asks-it-for-the-meshs-names.md)). ([ADR 0194](../../02-DECISIONS/0194-the-mesh-has-one-resolver-and-every-node-asks-it-for-the-meshs-names.md)).
**No node holds a copy.** The per-node resolver, its zones file and the mesh's region of `/etc/hosts` **No node holds a copy.** The per-node resolver, its zones file and the mesh's region of `/etc/hosts`
@@ -369,7 +369,7 @@ go: every resolution fault found on 2026-10-03 was a copy disagreeing with the t
read once at start, an operator's old line beside the mesh's, a node's resolver lent to a LAN. No read once at start, an operator's old line beside the mesh's, a node's resolver lent to a LAN. No
member's resolver answers a LAN; a router pointing at one is moved first. *Checked by `resolvectl` on member's resolver answers a LAN; a router pointing at one is moved first. *Checked by `resolvectl` on
each node (the tunnel's link, `mesh-resolver`, the suffix as routing domain), by no node but the each node (the tunnel's link, `mesh-resolver`, the suffix as routing domain), by no node but the
holder listening on port 53, and by the router's DHCP DNS option naming no node.* holder answering DNS on a private or LAN address, and by the router's DHCP DNS option naming no node.*
*What follows describes the per-node resolver this replaces — how it was built and why the roles were *What follows describes the per-node resolver this replaces — how it was built and why the roles were
split. The split stands; the serving role's scope is what moved.* split. The split stands; the serving role's scope is what moved.*