ADR 0191: the mesh resolves only its own names; a public name resolves publicly #320

Merged
jschoubben merged 1 commits from decision/0191-the-mesh-resolves-only-its-own-domain into main 2026-10-03 13:16:13 +00:00
Owner

The mesh published every routed public name into each machine's resolver at a private (tunnel) address (ADR 0066/0151). ace's resolver also answers its LAN since 2026-10-02, so non-members on that LAN — a phone — got tunnel addresses they cannot reach (mail: couldn't connect to 10.10.0.1:143).

Decision: only names under the mesh suffix (*.internal, incl. <label>.<node>.internal) get private answers; public names resolve publicly. Narrows 0066 and 0151 (marked in each); amends connectivity §2 and §5; open item lists the controller change.

Checks: records.py, index.py, cycle.py pass.

The mesh published every routed public name into each machine's resolver at a private (tunnel) address (ADR 0066/0151). ace's resolver also answers its LAN since 2026-10-02, so non-members on that LAN — a phone — got tunnel addresses they cannot reach (mail: couldn't connect to 10.10.0.1:143). Decision: only names under the mesh suffix (`*.internal`, incl. `<label>.<node>.internal`) get private answers; public names resolve publicly. Narrows 0066 and 0151 (marked in each); amends connectivity §2 and §5; open item lists the controller change. Checks: records.py, index.py, cycle.py pass.
jschoubben added 1 commit 2026-10-03 13:11:45 +00:00
Publishing every routed public name at a private address turned ace's LAN-facing resolver into an
outage for non-members: a phone got the control-node's tunnel address for the mail server. Routes
have internal names since 0151 and the proxy certifies public names publicly, so nothing needs the
private answer. Narrows 0066 and 0151; amends connectivity §2 and §5.
jschoubben merged commit 9873e951a9 into main 2026-10-03 13:16:13 +00:00
jschoubben deleted branch decision/0191-the-mesh-resolves-only-its-own-domain 2026-10-03 13:16:14 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#320