Found reviewing the resolver's conversion, before it is assigned anywhere. The resolver declares it listens from the mesh, so a converged node's filter admits queries from private-network addresses. A container on a network its module declared asks via the runtime, from the machine itself — admitted. A container on the runtime's default network asks from its own address on that network — dropped. So at the flip, such a container has no DNS.
It is the same split that decided which container survived the hub's address change tonight: the forge is on the default network and lost its database, the service beside it is not and was untouched (issue 109). And it matters doubly because 109's stronger answer — give a container no address and make it always ask the resolver — is only available if every container can reach it.
Nothing fails while the node is adopted; the predecessor's firewall is still in force. Asks whether the resolver should be reachable from the runtime's own networks by the interface a packet arrives on (the exception the mesh's guard already makes), or whether every module should be required to declare a network — which would have prevented 109 too.
Found reviewing the resolver's conversion, before it is assigned anywhere. The resolver declares it listens *from the mesh*, so a converged node's filter admits queries from private-network addresses. A container on a network its module declared asks via the runtime, from the machine itself — admitted. A container on the runtime's **default** network asks from its own address on that network — dropped. So at the flip, such a container has no DNS.
It is the same split that decided which container survived the hub's address change tonight: the forge is on the default network and lost its database, the service beside it is not and was untouched (issue 109). And it matters doubly because 109's stronger answer — give a container no address and make it always ask the resolver — is only available if every container can reach it.
Nothing fails while the node is adopted; the predecessor's firewall is still in force. Asks whether the resolver should be reachable from the runtime's own networks by the interface a packet arrives on (the exception the mesh's guard already makes), or whether every module should be required to declare a network — which would have prevented 109 too.
Found reviewing the resolver's conversion. Nothing fails while the node is adopted; it
fails at the flip, and it is the same split that decided which container survived the
hub's address change.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found reviewing the resolver's conversion, before it is assigned anywhere. The resolver declares it listens from the mesh, so a converged node's filter admits queries from private-network addresses. A container on a network its module declared asks via the runtime, from the machine itself — admitted. A container on the runtime's default network asks from its own address on that network — dropped. So at the flip, such a container has no DNS.
It is the same split that decided which container survived the hub's address change tonight: the forge is on the default network and lost its database, the service beside it is not and was untouched (issue 109). And it matters doubly because 109's stronger answer — give a container no address and make it always ask the resolver — is only available if every container can reach it.
Nothing fails while the node is adopted; the predecessor's firewall is still in force. Asks whether the resolver should be reachable from the runtime's own networks by the interface a packet arrives on (the exception the mesh's guard already makes), or whether every module should be required to declare a network — which would have prevented 109 too.