diff --git a/02-DECISIONS/0191-the-meshs-resolver-holds-only-the-meshs-own-names.md b/02-DECISIONS/0191-the-meshs-resolver-holds-only-the-meshs-own-names.md index f1d2b8e..be16cb4 100644 --- a/02-DECISIONS/0191-the-meshs-resolver-holds-only-the-meshs-own-names.md +++ b/02-DECISIONS/0191-the-meshs-resolver-holds-only-the-meshs-own-names.md @@ -14,11 +14,12 @@ supersedes-in-part: > **Progressive insight — 2026-10-03.** The first implementation told the mesh's names from public > ones by their spelling — a name ending in the mesh suffix — and this record said so: the Decision > read *"only names under its own suffix"*, and the roster check *"every name the roster carries ends -> in the mesh suffix"*. The mesh needs no such test: it composes both names of every route itself, -> `name` from the node's public domain and `internal-name` from its own domain under the serving node -> (ADR 0151), and publishes the second. Which names are its own is known from where each was -> composed. Both sentences now say that; what was decided — a public name is never given a private -> answer — is unchanged. +> in the mesh suffix"*. The mesh needs no such test, nor any per-route name: domains are a node's. A +> node has **one internal domain**, `.internal`, and every route on it is a name under that domain +> (ADR 0151), answered by one wildcard per node; a node has **one or more public domains**, which public +> DNS answers. So the mesh's resolver holds the nodes' internal domains and nothing else, and the roster +> carries the machines and no routed name. Both sentences now say that; what was decided — a public +> name is never given a private answer — is unchanged. ## Context @@ -72,8 +73,8 @@ every public name the mesh serves, is forwarded and resolves publicly. Chosen. ## Decision -**The mesh publishes into internal resolution only the names it composes for itself** — a -machine's name, and each route's `internal-name`, never a route's public `name`. A machine's name, +**The mesh's resolver holds each node's internal domain and nothing else** — `.internal` and +everything under it, at that node's private address. A machine's name, and through it every `