diff --git a/02-DECISIONS/0191-the-meshs-resolver-holds-only-the-meshs-own-names.md b/02-DECISIONS/0191-the-meshs-resolver-holds-only-the-meshs-own-names.md index 8d11a12..be16cb4 100644 --- a/02-DECISIONS/0191-the-meshs-resolver-holds-only-the-meshs-own-names.md +++ b/02-DECISIONS/0191-the-meshs-resolver-holds-only-the-meshs-own-names.md @@ -11,6 +11,16 @@ supersedes-in-part: # 191. The mesh's resolver holds only the mesh's own names; a public name resolves publicly +> **Progressive insight — 2026-10-03.** The first implementation told the mesh's names from public +> ones by their spelling — a name ending in the mesh suffix — and this record said so: the Decision +> read *"only names under its own suffix"*, and the roster check *"every name the roster carries ends +> in the mesh suffix"*. The mesh needs no such test, nor any per-route name: domains are a node's. A +> node has **one internal domain**, `.internal`, and every route on it is a name under that domain +> (ADR 0151), answered by one wildcard per node; a node has **one or more public domains**, which public +> DNS answers. So the mesh's resolver holds the nodes' internal domains and nothing else, and the roster +> carries the machines and no routed name. Both sentences now say that; what was decided — a public +> name is never given a private answer — is unchanged. + ## Context **[ADR 0066](0066-public-routing-is-name-agnostic.md) published every routed name into internal @@ -63,7 +73,8 @@ every public name the mesh serves, is forwarded and resolves publicly. Chosen. ## Decision -**The mesh publishes into internal resolution only names under its own suffix.** A machine's name, +**The mesh's resolver holds each node's internal domain and nothing else** — `.internal` and +everything under it, at that node's private address. A machine's name, and through it every `