From 7e9d0dfe7b6f6385bab0b159cb108a6e068e5be3 Mon Sep 17 00:00:00 2001 From: jochen Date: Wed, 7 Oct 2026 21:35:21 +0200 Subject: [PATCH] ADR 0247: say what is to confirm live about resolved and the resolver file, not a guess --- ...-routes-names-by-domain-through-a-resolver-of-its-own.md | 6 +++--- .../01-to-be/50-split-dns-on-a-machine-with-a-vpn-client.md | 4 ++-- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/02-DECISIONS/0247-a-machine-with-a-vpn-client-routes-names-by-domain-through-a-resolver-of-its-own.md b/02-DECISIONS/0247-a-machine-with-a-vpn-client-routes-names-by-domain-through-a-resolver-of-its-own.md index 181df92b..7a66b666 100644 --- a/02-DECISIONS/0247-a-machine-with-a-vpn-client-routes-names-by-domain-through-a-resolver-of-its-own.md +++ b/02-DECISIONS/0247-a-machine-with-a-vpn-client-routes-names-by-domain-through-a-resolver-of-its-own.md @@ -203,9 +203,9 @@ life of the tunnel, and in the kept write until the next boot. - **Containers keep the resolvers they started with** (ADR 0223's consequence, unchanged). On the laptop a container started before the resolver is assigned keeps the mesh's two resolvers until it restarts. That is correct for mesh names, but it means the company's names do not reach that container. -- **Harder:** while a write stands, resolved also reads the VPN client's servers from the file (its - "foreign" mode). This lasts seconds for a taken write and up to 90 s for one nothing took. It is the - same window the machine has today, shorter. +- **To confirm live:** resolved takes no servers from `/etc/resolv.conf` once its own are configured + (`DNS=` in its drop-in). So neither a VPN client's write, nor the file's own address, should become one + of its servers. The live test reads `routes` while a write stands to confirm it. - **Unassigning the resolver** brings the uplink holder's rendering back. The node-engine hands a whole file from one owner to the next at the same path, so the file is not removed in between. diff --git a/03-DESIGN/01-to-be/50-split-dns-on-a-machine-with-a-vpn-client.md b/03-DESIGN/01-to-be/50-split-dns-on-a-machine-with-a-vpn-client.md index 1341de5a..9c4f1426 100644 --- a/03-DESIGN/01-to-be/50-split-dns-on-a-machine-with-a-vpn-client.md +++ b/03-DESIGN/01-to-be/50-split-dns-on-a-machine-with-a-vpn-client.md @@ -124,8 +124,8 @@ resolver's hold, and is therefore raised. A VPN that tells resolved its link's D - The client's search domains route full names. They do not complete short ones. - resolved down is no names on that machine. Its `unit` health, and the node-engine's names check against the address the file lists, say so. -- While a write stands, resolved reads the client's servers from the file too. This lasts seconds for a - taken write and 90 s for one nothing took. +- resolved should take no servers from the resolver file, because its own are configured. The live test + confirms this while a write stands. - A container started before the resolver keeps the mesh's two resolvers until it restarts. ## Phases