ADR 0194: why every node needs a stub, and the systemd-resolved module that provides it

This commit is contained in:
2026-10-03 21:50:33 +02:00
parent 1de4a5f25e
commit 6b6ff76a19
2 changed files with 23 additions and 10 deletions
+3 -2
View File
@@ -357,8 +357,9 @@ machine — declared or not — is what a nameserver in `resolv.conf` would be f
seat of capacity one, placed on the node every tunnel converges on. It holds one wildcard per node —
`<node>.internal` and everything under it — and listens on the private network only. Every node's
`node-resolver-config` routes the mesh's suffix to it and leaves every other name with public
resolvers; plain `resolv.conf` cannot route by domain, so the asking side is a stub that can
(systemd-resolved, the tunnel's link carrying the suffix as its routing domain). The container runtime
resolvers; plain `resolv.conf` cannot route by domain, so the asking side is a stub that can — a
`systemd-resolved` module claiming `node-resolver-config` in place of `resolv-conf`, routing the suffix
to `mesh-resolver`. The container runtime
cannot use a loopback stub, so its `dns` names `mesh-resolver`, which forwards public names for
containers — the one place a public name passes through the mesh
([ADR 0194](../../02-DECISIONS/0194-the-mesh-has-one-resolver-and-every-node-asks-it-for-the-meshs-names.md)).