ADR 0247: say exactly where the VPN's domains go and do not
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered

This commit is contained in:
jochen
2026-10-07 21:35:40 +02:00
parent 7e9d0dfe7b
commit 6373ca815b
@@ -155,8 +155,8 @@ file, the guard does three things:
the module's file back at once.
- Otherwise it puts the module's file back **after 90 s**.
What the resolver says anywhere else is when, the writer's name and what became of each write, never a
server or a domain.
Of an outside write, the resolver says nothing beyond the machine except when it happened, the writer's
name and what became of it. It never says a server or a domain from the write.
**6. The VPN client's module carries its own adapter.** The `forticlient` module requires `split-dns` and
runs an adapter, as root, that does four things:
@@ -177,9 +177,11 @@ no finding. A write nothing took stands for 90 s, so the node-engine sees it twi
adapter not running, no tunnel within its wait, and a route refused. The guard then puts the file back,
and the finding clears.
**8. The VPN's domains never leave the machine.** They are never in the mesh's store, the controller's
renders, the mesh's resolvers, the bus or another machine. They live in resolved's per-link state for the
life of the tunnel, and in the kept write until the next boot.
**8. The VPN's domains stay on the machine.** They are never in the mesh's store, the controller's
renders, the mesh's resolvers, an event or another machine's files. The adapter hands them over on the
machine, never over the bus. They live in resolved's per-link state for the life of the tunnel, and in the
kept write until the next boot. They cross the bus only as the answer to `routes` when the operator asks
it, and nothing keeps that answer.
## Consequences