ADR 0247: say exactly where the VPN's domains go and do not
This commit is contained in:
+7
-5
@@ -155,8 +155,8 @@ file, the guard does three things:
|
||||
the module's file back at once.
|
||||
- Otherwise it puts the module's file back **after 90 s**.
|
||||
|
||||
What the resolver says anywhere else is when, the writer's name and what became of each write, never a
|
||||
server or a domain.
|
||||
Of an outside write, the resolver says nothing beyond the machine except when it happened, the writer's
|
||||
name and what became of it. It never says a server or a domain from the write.
|
||||
|
||||
**6. The VPN client's module carries its own adapter.** The `forticlient` module requires `split-dns` and
|
||||
runs an adapter, as root, that does four things:
|
||||
@@ -177,9 +177,11 @@ no finding. A write nothing took stands for 90 s, so the node-engine sees it twi
|
||||
adapter not running, no tunnel within its wait, and a route refused. The guard then puts the file back,
|
||||
and the finding clears.
|
||||
|
||||
**8. The VPN's domains never leave the machine.** They are never in the mesh's store, the controller's
|
||||
renders, the mesh's resolvers, the bus or another machine. They live in resolved's per-link state for the
|
||||
life of the tunnel, and in the kept write until the next boot.
|
||||
**8. The VPN's domains stay on the machine.** They are never in the mesh's store, the controller's
|
||||
renders, the mesh's resolvers, an event or another machine's files. The adapter hands them over on the
|
||||
machine, never over the bus. They live in resolved's per-link state for the life of the tunnel, and in the
|
||||
kept write until the next boot. They cross the bus only as the answer to `routes` when the operator asks
|
||||
it, and nothing keeps that answer.
|
||||
|
||||
## Consequences
|
||||
|
||||
|
||||
Reference in New Issue
Block a user