- dnsmasq holds mesh-dns-resolver: provides wildcard-resolution mesh-wide, forwards every declared
zone (zones fact), listens on the private address and loopback only, reads no hosts file and no
operator's files, and no longer writes the container runtime's dns.
- resolv-conf names the mesh's resolver by address, then 1.1.1.1, timeout 1, one attempt; it now
holds the runtime's live-restore, which dnsmasq held and every node needs.
- resolved-split-dns routes the suffix to the mesh's resolver by address, not 127.0.0.1.
- hosts: new module holding node-hosts-file — the machine's own lines in its block of /etc/hosts,
the operator's lines kept, changed by entries/add/remove through sudo -n.