ADR 0194: why every node needs a stub, and the systemd-resolved module that provides it
This commit is contained in:
@@ -357,8 +357,9 @@ machine — declared or not — is what a nameserver in `resolv.conf` would be f
|
||||
seat of capacity one, placed on the node every tunnel converges on. It holds one wildcard per node —
|
||||
`<node>.internal` and everything under it — and listens on the private network only. Every node's
|
||||
`node-resolver-config` routes the mesh's suffix to it and leaves every other name with public
|
||||
resolvers; plain `resolv.conf` cannot route by domain, so the asking side is a stub that can
|
||||
(systemd-resolved, the tunnel's link carrying the suffix as its routing domain). The container runtime
|
||||
resolvers; plain `resolv.conf` cannot route by domain, so the asking side is a stub that can — a
|
||||
`systemd-resolved` module claiming `node-resolver-config` in place of `resolv-conf`, routing the suffix
|
||||
to `mesh-resolver`. The container runtime
|
||||
cannot use a loopback stub, so its `dns` names `mesh-resolver`, which forwards public names for
|
||||
containers — the one place a public name passes through the mesh
|
||||
([ADR 0194](../../02-DECISIONS/0194-the-mesh-has-one-resolver-and-every-node-asks-it-for-the-meshs-names.md)).
|
||||
|
||||
Reference in New Issue
Block a user