ADR 0191: domains are a node's — the resolver holds each node's internal domain, nothing else #323

Merged
jschoubben merged 2 commits from decision/0191-names-by-origin into main 2026-10-03 19:12:27 +00:00
2 changed files with 14 additions and 14 deletions
Showing only changes of commit 2344bfb69b - Show all commits
@@ -14,11 +14,12 @@ supersedes-in-part:
> **Progressive insight — 2026-10-03.** The first implementation told the mesh's names from public > **Progressive insight — 2026-10-03.** The first implementation told the mesh's names from public
> ones by their spelling — a name ending in the mesh suffix — and this record said so: the Decision > ones by their spelling — a name ending in the mesh suffix — and this record said so: the Decision
> read *"only names under its own suffix"*, and the roster check *"every name the roster carries ends > read *"only names under its own suffix"*, and the roster check *"every name the roster carries ends
> in the mesh suffix"*. The mesh needs no such test: it composes both names of every route itself, > in the mesh suffix"*. The mesh needs no such test, nor any per-route name: domains are a node's. A
> `name` from the node's public domain and `internal-name` from its own domain under the serving node > node has **one internal domain**, `<node>.internal`, and every route on it is a name under that domain
> (ADR 0151), and publishes the second. Which names are its own is known from where each was > (ADR 0151), answered by one wildcard per node; a node has **one or more public domains**, which public
> composed. Both sentences now say that; what was decided — a public name is never given a private > DNS answers. So the mesh's resolver holds the nodes' internal domains and nothing else, and the roster
> answer — is unchanged. > carries the machines and no routed name. Both sentences now say that; what was decided — a public
> name is never given a private answer — is unchanged.
## Context ## Context
@@ -72,8 +73,8 @@ every public name the mesh serves, is forwarded and resolves publicly. Chosen.
## Decision ## Decision
**The mesh publishes into internal resolution only the names it composes for itself** — a **The mesh's resolver holds each node's internal domain and nothing else** — `<node>.internal` and
machine's name, and each route's `internal-name`, never a route's public `name`. A machine's name, everything under it, at that node's private address. A machine's name,
and through it every `<label>.<node>.internal`, resolve to that machine's private address. **A public and through it every `<label>.<node>.internal`, resolve to that machine's private address. **A public
name is never given a private answer by the mesh**: it resolves through public DNS to the public name is never given a private answer by the mesh**: it resolves through public DNS to the public
address, from members and non-members alike. address, from members and non-members alike.
@@ -103,8 +104,8 @@ reachability — the lab — certifies its internal names and has no public name
**How each is checked:** **How each is checked:**
- **The roster:** the controller's catalogue tests assert that the names served are routes' - **The roster:** the controller's tests assert that the roster names the machines and nothing
internal names and that no route's public name is among them — one published fails the build. else — a routed name in it, public or internal, fails the build.
- **On a machine:** asking the machine's resolver for a public name the mesh serves returns the - **On a machine:** asking the machine's resolver for a public name the mesh serves returns the
public address, and asking it for that route's internal name returns the private one. Asked from a public address, and asking it for that route's internal name returns the private one. Asked from a
non-member on a LAN the resolver answers, the first must hold as well. non-member on a LAN the resolver answers, the first must hold as well.
+4 -5
View File
@@ -425,16 +425,15 @@ the cost of not seeing it is inventing a mechanism that already exists.
### The mesh resolves only its own names; a public name resolves publicly ### The mesh resolves only its own names; a public name resolves publicly
**The mesh's resolver holds the names the mesh composes for itself and nothing else** — every **The mesh's resolver holds each node's internal domain and nothing else** — `<node>.internal` and
machine's name, and every route's internal name `<label>.<node>.internal` everything under it, so every route's internal name `<label>.<node>.internal` with no line of its own
([ADR 0151](../../02-DECISIONS/0151-a-routes-internal-name-is-composed-under-the-node-that-serves-it.md)). ([ADR 0151](../../02-DECISIONS/0151-a-routes-internal-name-is-composed-under-the-node-that-serves-it.md)).
**A public name the mesh serves is never given a private answer**: it is forwarded and resolves to the **A node's public domains — one or more — are never given a private answer**: it is forwarded and resolves to the
public address, from a member and from anything else the resolver answers — a resolver may serve a public address, from a member and from anything else the resolver answers — a resolver may serve a
machine's LAN, and a phone on that LAN must get the address it can reach machine's LAN, and a phone on that LAN must get the address it can reach
([ADR 0191](../../02-DECISIONS/0191-the-meshs-resolver-holds-only-the-meshs-own-names.md)). Inside the ([ADR 0191](../../02-DECISIONS/0191-the-meshs-resolver-holds-only-the-meshs-own-names.md)). Inside the
mesh, a routed service is reached, and certified by the internal authority, under its internal name. mesh, a routed service is reached, and certified by the internal authority, under its internal name.
*Checked by the controller's catalogue tests — the names served are routes' internal names, and no *Checked by the controller's tests — the roster names the machines and no routed name —
route's public name is among them —
and on a machine by asking its resolver for a public name the mesh serves: the answer is the public and on a machine by asking its resolver for a public name the mesh serves: the answer is the public
address.* address.*