diff --git a/modules/resolv-conf/module.json b/modules/resolv-conf/module.json index 7fb0acb..20634a8 100644 --- a/modules/resolv-conf/module.json +++ b/modules/resolv-conf/module.json @@ -17,7 +17,7 @@ "type": "file", "path": "/etc/resolv.conf", "mode": "0644", - "content": "# Managed by the mesh.\n#\n# For a machine where nothing else owns this file. On one where systemd-resolved\n# or NetworkManager does, assign that module instead — this one and those claim\n# the same thing, so the mesh refuses the pair rather than letting them take\n# turns overwriting each other, which is the failure this claim exists to stop.\n#\n# The mesh's one resolver first (novox/hq ADR 0194, 0196), by address — a machine\n# cannot resolve the name of the thing it resolves names with. It answers the\n# mesh's names itself and forwards every other name. A public resolver second,\n# asked only when the first does not answer at all — its machine or the tunnel\n# down, a captive portal holding the tunnel back — so public names keep\n# resolving then. An answer from the first, \"no such name\" included, is final,\n# so a mesh name is never asked of the public one while the mesh's answers. One\n# second and one attempt, so the wait before the fallback is short. Containers\n# copy these two lines from their machine.\nnameserver ${bound:wildcard-resolution:address}\nnameserver 1.1.1.1\noptions timeout:1 attempts:1 edns0\n" + "content": "# Managed by the mesh.\n#\n# The machine's network manager is told to leave this file alone by the module\n# holding its uplink, which the mesh requires beside this one (novox/hq ADR 0117,\n# 0220): without it, the first change of network would rewrite the file.\n#\n# The mesh's one resolver first (novox/hq ADR 0194, 0196), by address — a machine\n# cannot resolve the name of the thing it resolves names with. It answers the\n# mesh's names itself and forwards every other name. A public resolver second,\n# asked only when the first does not answer at all — its machine or the tunnel\n# down, a captive portal holding the tunnel back — so public names keep\n# resolving then. An answer from the first, \"no such name\" included, is final,\n# so a mesh name is never asked of the public one while the mesh's answers. One\n# second and one attempt, so the wait before the fallback is short. Containers\n# copy these two lines from their machine.\nnameserver ${bound:wildcard-resolution:address}\nnameserver 1.1.1.1\noptions timeout:1 attempts:1 edns0\n" } ] } diff --git a/modules/resolved-split-dns/module.json b/modules/resolved-split-dns/module.json deleted file mode 100644 index b875d8e..0000000 --- a/modules/resolved-split-dns/module.json +++ /dev/null @@ -1,39 +0,0 @@ -{ - "module": "resolved-split-dns", - "version": "1", - "slug": "splitdns", - "requires": [ - "wildcard-resolution" - ], - "claims": [ - { - "name": "node-resolver-config", - "scope": "node" - } - ], - "resources": [ - { - "id": "drop-in", - "type": "directory", - "path": "/etc/systemd/resolved.conf.d", - "mode": "0755" - }, - { - "id": "route", - "type": "file", - "path": "/etc/systemd/resolved.conf.d/mesh.conf", - "mode": "0644", - "content": "# Managed by the mesh.\n#\n# **Only the mesh's names.** The tilde makes this a routing domain rather than a\n# search domain: queries under it go to the resolver below, and everything else\n# keeps going wherever this machine already sent it. A resolver that took over\n# all of DNS would be this module claiming the machine's whole network, which\n# is not what it says it claims. The mesh's resolver can forward the rest too;\n# this module is for a machine that wants systemd-resolved to stay in charge of\n# that, and only lends it the mesh's suffix.\n#\n# The mesh's one resolver (novox/hq ADR 0194), by its private address — a\n# machine cannot resolve the name of the thing it resolves names with.\n[Resolve]\nDNS=${bound:wildcard-resolution:address}\nDomains=~internal\n" - }, - { - "id": "resolved", - "type": "service", - "unit": "systemd-resolved.service", - "state": "running", - "boot": "enabled", - "restart-on": [ - "route" - ] - } - ] -}