ADR 0191: domains are a node's — one internal, one or more public; the roster is the machines

This commit is contained in:
2026-10-03 16:10:38 +02:00
parent ca8a865e73
commit 2344bfb69b
2 changed files with 14 additions and 14 deletions
+4 -5
View File
@@ -425,16 +425,15 @@ the cost of not seeing it is inventing a mechanism that already exists.
### The mesh resolves only its own names; a public name resolves publicly
**The mesh's resolver holds the names the mesh composes for itself and nothing else** — every
machine's name, and every route's internal name `<label>.<node>.internal`
**The mesh's resolver holds each node's internal domain and nothing else** — `<node>.internal` and
everything under it, so every route's internal name `<label>.<node>.internal` with no line of its own
([ADR 0151](../../02-DECISIONS/0151-a-routes-internal-name-is-composed-under-the-node-that-serves-it.md)).
**A public name the mesh serves is never given a private answer**: it is forwarded and resolves to the
**A node's public domains — one or more — are never given a private answer**: it is forwarded and resolves to the
public address, from a member and from anything else the resolver answers — a resolver may serve a
machine's LAN, and a phone on that LAN must get the address it can reach
([ADR 0191](../../02-DECISIONS/0191-the-meshs-resolver-holds-only-the-meshs-own-names.md)). Inside the
mesh, a routed service is reached, and certified by the internal authority, under its internal name.
*Checked by the controller's catalogue tests — the names served are routes' internal names, and no
route's public name is among them —
*Checked by the controller's tests — the roster names the machines and no routed name —
and on a machine by asking its resolver for a public name the mesh serves: the answer is the public
address.*