ADR 0194: the mesh has one resolver, and every node asks it for the mesh's names #326

Merged
jschoubben merged 3 commits from decision/0194-the-mesh-has-one-resolver into main 2026-10-03 19:51:04 +00:00
2 changed files with 8 additions and 7 deletions
Showing only changes of commit 13e28e6873 - Show all commits
@@ -133,8 +133,9 @@ as a LAN's DNS server is pointed elsewhere before that node stops answering.
- **Asking:** on each node, `resolvectl` shows the tunnel's link with `mesh-resolver` and the suffix as
its routing domain; a name under `.internal` is answered by it, and a public name is answered
without it (its query log shows no public name from a node).
- **No copies:** no node but the holder listens on port 53, and no node's `/etc/hosts` carries a mesh
region.
- **No copies:** no node but the holder answers DNS on a private or LAN address — every other node's
port 53 is systemd-resolved's loopback stub and nothing else — and no node's `/etc/hosts` carries a
mesh region.
- **A LAN:** the router's DHCP DNS option names no node's address.
## References
+5 -5
View File
@@ -358,10 +358,10 @@ seat of capacity one, placed on the node every tunnel converges on. It holds one
`<node>.internal` and everything under it — and listens on the private network only. Every node's
`node-resolver-config` routes the mesh's suffix to it and leaves every other name with public
resolvers; plain `resolv.conf` cannot route by domain, so the asking side is a stub that can — a
`systemd-resolved` module claiming `node-resolver-config` in place of `resolv-conf`, routing the suffix
to `mesh-resolver`. The container runtime
cannot use a loopback stub, so its `dns` names `mesh-resolver`, which forwards public names for
containers — the one place a public name passes through the mesh
`systemd-resolved` module claiming `node-resolver-config` in place of `resolv-conf`, routing the
suffix to `mesh-resolver`. The container runtime cannot use a loopback stub, so its `dns` names
`mesh-resolver`, which forwards public names for containers — the one place a public name passes
through the mesh
([ADR 0194](../../02-DECISIONS/0194-the-mesh-has-one-resolver-and-every-node-asks-it-for-the-meshs-names.md)).
**No node holds a copy.** The per-node resolver, its zones file and the mesh's region of `/etc/hosts`
@@ -369,7 +369,7 @@ go: every resolution fault found on 2026-10-03 was a copy disagreeing with the t
read once at start, an operator's old line beside the mesh's, a node's resolver lent to a LAN. No
member's resolver answers a LAN; a router pointing at one is moved first. *Checked by `resolvectl` on
each node (the tunnel's link, `mesh-resolver`, the suffix as routing domain), by no node but the
holder listening on port 53, and by the router's DHCP DNS option naming no node.*
holder answering DNS on a private or LAN address, and by the router's DHCP DNS option naming no node.*
*What follows describes the per-node resolver this replaces — how it was built and why the roles were
split. The split stands; the serving role's scope is what moved.*