From f4e81074d3f2c2ab690317dd2ceaa94ede787968 Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 31 Aug 2026 12:15:12 +0200 Subject: [PATCH] Which resolver is a claim, and was decided before it was asked MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit A resolver takes over /etc/resolv.conf, which is a singular resource — ADR 0009 lists it in the table beside the seat and pid 1. So choosing between resolved, dnsmasq and unbound is assigning a module, per machine, and the mesh refuses two rather than letting them fight over the file. Recorded because it was treated as an open question two days after being decided, which is the argument for that table being a table. --- 03-DESIGN/01-to-be/08-connectivity.md | 27 +++++++++++++++++++++++++-- 1 file changed, 25 insertions(+), 2 deletions(-) diff --git a/03-DESIGN/01-to-be/08-connectivity.md b/03-DESIGN/01-to-be/08-connectivity.md index 95a4a96..5180bd0 100644 --- a/03-DESIGN/01-to-be/08-connectivity.md +++ b/03-DESIGN/01-to-be/08-connectivity.md @@ -278,13 +278,36 @@ somebody starts by hand is not the mesh's to configure, and reaching into every machine — declared or not — is what a nameserver in `resolv.conf` would be for. **That is now the second reason to want a resolver**, and it is a different one from the trigger -above. Both remain unmet needs rather than plans: +above: | | | |---|---| -| names that are not one-per-node | `postgres.internal` meaning *wherever the database is* | +| names that are not one-per-node | a service named under a machine — `postgres.novox.internal` | | containers the mesh did not declare | anything a person or another tool starts on a node | +### Which resolver is not a question the mesh answers + +*Written 2026-08-31, after treating it as open when it had been decided two days earlier.* + +**A resolver takes over `/etc/resolv.conf`, which is a singular resource, so it is a claim** — +[ADR 0009](../../02-DECISIONS/0009-modules-and-the-graph.md) lists it in the table beside the seat +and pid 1. Choosing between resolved, dnsmasq and unbound is **assigning a module**, per machine, +and two of them cannot both be assigned there: + +> `resolved-config and dnsmasq both claim "/etc/resolv.conf", and only one thing may hold it per node` + +So there is nothing global to settle and nothing for the mesh to guess. One machine can use what +systemd already owns and another can run dnsmasq, and neither has to know about the other. + +**What the mesh contributes is the part only it can know**: which machines exist and where. That +is `mesh-resolver`, which writes one file and holds no claim, because writing a file takes nothing +over. A daemon module requires that data and claims the resolver — so swapping the daemon changes +that module and nothing else. + +**This was recorded on 2026-08-29 and reopened as an unanswered question on the 31st.** Which is +the argument for the table in ADR 0009 being a table: the pattern is only obvious once seen, and +the cost of not seeing it is inventing a mechanism that already exists. + ## 3 — Exposure Settled by [ADR 0007](../../02-DECISIONS/0007-connectivity.md); summarised here because