One mesh-scoped seat mesh-resolver (capacity 1) on the node every tunnel converges on; holds each node's internal domain; listens on the private network only.
Each node's node-resolver-config routes only the mesh suffix to it (systemd-resolved as routing stub); public names stay with public resolvers.
Containers: the runtime's dns names mesh-resolver, which forwards public names for them (stated as the one place a public name passes through the mesh).
node-dns-resolver retired with every per-node copy (zones file, hosts region).
A LAN's resolver is not the mesh's; a router pointing at a node is moved first.
Migration order fixed in four steps.
Narrows ADR 0121 (marked). Amends connectivity §2 (new subsection + open item) and the seats table (status back to in-progress). records/index/cycle pass.
- One mesh-scoped seat `mesh-resolver` (capacity 1) on the node every tunnel converges on; holds each node's internal domain; listens on the private network only.
- Each node's `node-resolver-config` routes only the mesh suffix to it (systemd-resolved as routing stub); public names stay with public resolvers.
- Containers: the runtime's `dns` names `mesh-resolver`, which forwards public names for them (stated as the one place a public name passes through the mesh).
- `node-dns-resolver` retired with every per-node copy (zones file, hosts region).
- A LAN's resolver is not the mesh's; a router pointing at a node is moved first.
- Migration order fixed in four steps.
Narrows ADR 0121 (marked). Amends connectivity §2 (new subsection + open item) and the seats table (status back to in-progress). records/index/cycle pass.
Every resolution fault found on 2026-10-03 was a per-node copy disagreeing with the truth: a hosts
file read once, an operator's old line beside the mesh's, a node's resolver lent to a LAN. Every
tunnel already converges on one node. Retires node-dns-resolver for a mesh-scoped mesh-resolver;
nodes route only the mesh's suffix to it. Narrows 0121; amends connectivity §2 and the seats.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
mesh-resolver(capacity 1) on the node every tunnel converges on; holds each node's internal domain; listens on the private network only.node-resolver-configroutes only the mesh suffix to it (systemd-resolved as routing stub); public names stay with public resolvers.dnsnamesmesh-resolver, which forwards public names for them (stated as the one place a public name passes through the mesh).node-dns-resolverretired with every per-node copy (zones file, hosts region).Narrows ADR 0121 (marked). Amends connectivity §2 (new subsection + open item) and the seats table (status back to in-progress). records/index/cycle pass.