Replaces ADR 0194's asking side. Each node's /etc/resolv.conf (existing resolv-conf module) names mesh-resolver first and a public resolver second, timeout:1 attempts:1. The mesh resolver answers .internal and forwards everything else; the public one is asked only when the mesh's is unreachable. Containers copy the machine's non-loopback resolvers, so no runtime dns.
Dropped: the systemd-resolved module and the runtime dns naming mesh-resolver. Kept from 0194: one mesh-resolver on the node every tunnel converges on, retirement of node-dns-resolver and per-node copies, a LAN's resolver not being the mesh's.
LAN devices are unaffected by this choice: they take DNS from the router, which step 3 points at itself (verified: the router answers public names correctly; the unifi module has unifi_set_network_dns).
Replaces ADR 0194's asking side. Each node's `/etc/resolv.conf` (existing `resolv-conf` module) names `mesh-resolver` first and a public resolver second, `timeout:1 attempts:1`. The mesh resolver answers `.internal` and forwards everything else; the public one is asked only when the mesh's is unreachable. Containers copy the machine's non-loopback resolvers, so no runtime `dns`.
Dropped: the `systemd-resolved` module and the runtime `dns` naming `mesh-resolver`. Kept from 0194: one `mesh-resolver` on the node every tunnel converges on, retirement of `node-dns-resolver` and per-node copies, a LAN's resolver not being the mesh's.
LAN devices are unaffected by this choice: they take DNS from the router, which step 3 points at itself (verified: the router answers public names correctly; the `unifi` module has `unifi_set_network_dns`).
ADR 0194 marked; connectivity §2 amended. records/index/cycle pass.
ADR 0194 rejected sending every query to the mesh's resolver because a node with its tunnel down
would resolve nothing; a public resolver listed second answers exactly then. That drops the
systemd-resolved stub and the runtime's dns: containers copy the machine's resolvers. Narrows 0194;
amends connectivity §2.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Replaces ADR 0194's asking side. Each node's
/etc/resolv.conf(existingresolv-confmodule) namesmesh-resolverfirst and a public resolver second,timeout:1 attempts:1. The mesh resolver answers.internaland forwards everything else; the public one is asked only when the mesh's is unreachable. Containers copy the machine's non-loopback resolvers, so no runtimedns.Dropped: the
systemd-resolvedmodule and the runtimednsnamingmesh-resolver. Kept from 0194: onemesh-resolveron the node every tunnel converges on, retirement ofnode-dns-resolverand per-node copies, a LAN's resolver not being the mesh's.LAN devices are unaffected by this choice: they take DNS from the router, which step 3 points at itself (verified: the router answers public names correctly; the
unifimodule hasunifi_set_network_dns).ADR 0194 marked; connectivity §2 amended. records/index/cycle pass.