Read against hal/modules/dnsmasq-app (hal dnsmasq-app conversion, hq 08-connectivity). Pairs with mesh-controller convert/dnsmasq-from-hal, which adds ${machine:address} and writes local=/<suffix>/ into the node-zones fact — merge that first, or the dnsmasq module's runtime-dns file is refused at composition.
What the predecessor does on a machine: dnsmasq answers every name — the mesh's own itself, the rest forwarded to 1.1.1.1 and 8.8.8.8 (its module's defaults); resolv.conf names it alone at 127.0.0.1; the container runtime's dns is the machine's tunnel address.
What the module does now:
dnsmasq: keeps no-resolv (the documented loop stays impossible) and forwards to the same two explicit upstreams; listens on mesh0 and 127.0.0.1 (not .53/.54, which systemd-resolved holds; .55 dropped — one address, the one every machine's resolv.conf already names); domain-needed, bogus-priv, bind-dynamic; requires mesh-addressing; writes {"dns":["${machine:address}"]}into/etc/docker/daemon.json (ADR 0102), no runtime restart ordered — the runtime reads dns at start, not on reload, and a restart stops every container; on the machine this replaces the value is already there.
resolv-conf: nameserver 127.0.0.1 alone plus options edns0, as the predecessor wrote; the placeholder second nameserver was a fallback nothing ever reached.
resolved-split-dns: follows the address (DNS=127.0.0.1); still routes only the suffix, for a machine that keeps systemd-resolved in charge of the rest.
The machines file /etc/mesh-resolver/nodes.conf is the node-zones fact the manifest already asked for; the dead mesh-resolver/resolver-data constants are removed in the controller. It now carries local=/<suffix>/ too.
mDNS/avahi not carried: no module does it, and 08-connectivity says mesh names are not multicast names.
Not settled here (see the controller PR body): the predecessor's per-node DNSMASQ_SPLIT_DNS/local-domain entries have no nox equivalent; a container on the runtime's default bridge on a converged node is filtered from port 53 (from: mesh); Domains=~internal in resolved-split-dns still hard-codes the default suffix.
Tests: mesh-controller internal/catalogue/resolver_manifests_test.go parses and composes these three manifests from this checkout; cmd/mesh-controller composes the resolver's machines file on a real mesh and again after a node leaves.
Read against hal/modules/dnsmasq-app (hal dnsmasq-app conversion, hq 08-connectivity). Pairs with mesh-controller `convert/dnsmasq-from-hal`, which adds `${machine:address}` and writes `local=/<suffix>/` into the `node-zones` fact — merge that first, or the dnsmasq module's runtime-dns file is refused at composition.
**What the predecessor does on a machine:** dnsmasq answers every name — the mesh's own itself, the rest forwarded to 1.1.1.1 and 8.8.8.8 (its module's defaults); resolv.conf names it alone at 127.0.0.1; the container runtime's `dns` is the machine's tunnel address.
**What the module does now:**
- `dnsmasq`: keeps `no-resolv` (the documented loop stays impossible) and forwards to the same two explicit upstreams; listens on `mesh0` and `127.0.0.1` (not .53/.54, which systemd-resolved holds; .55 dropped — one address, the one every machine's resolv.conf already names); `domain-needed`, `bogus-priv`, `bind-dynamic`; requires `mesh-addressing`; writes `{"dns":["${machine:address}"]}` *into* `/etc/docker/daemon.json` (ADR 0102), no runtime restart ordered — the runtime reads `dns` at start, not on reload, and a restart stops every container; on the machine this replaces the value is already there.
- `resolv-conf`: `nameserver 127.0.0.1` alone plus `options edns0`, as the predecessor wrote; the placeholder second nameserver was a fallback nothing ever reached.
- `resolved-split-dns`: follows the address (`DNS=127.0.0.1`); still routes only the suffix, for a machine that keeps systemd-resolved in charge of the rest.
- The machines file `/etc/mesh-resolver/nodes.conf` is the `node-zones` fact the manifest already asked for; the dead `mesh-resolver`/`resolver-data` constants are removed in the controller. It now carries `local=/<suffix>/` too.
- mDNS/avahi not carried: no module does it, and 08-connectivity says mesh names are not multicast names.
**Not settled here (see the controller PR body):** the predecessor's per-node `DNSMASQ_SPLIT_DNS`/local-domain entries have no nox equivalent; a container on the runtime's *default* bridge on a converged node is filtered from port 53 (`from: mesh`); `Domains=~internal` in resolved-split-dns still hard-codes the default suffix.
Tests: mesh-controller `internal/catalogue/resolver_manifests_test.go` parses and composes these three manifests from this checkout; `cmd/mesh-controller` composes the resolver's machines file on a real mesh and again after a node leaves.
Read against hal/modules/dnsmasq-app (hal dnsmasq-app conversion, hq 08-connectivity).
On the machines it runs, the predecessor's dnsmasq answers every name: the mesh's own
itself, the rest forwarded to 1.1.1.1 and 8.8.8.8, its module's defaults; resolv.conf
names it alone at 127.0.0.1, and the container runtime's dns is the machine's tunnel
address, so the host and every container resolve the world through it. The nox module
forwarded nothing, listened on 127.0.0.55 — a convention of its own beside the one every
machine already followed — and read a machines file that the module's `facts` already
asks the mesh for, so taking it would have left an adopted machine with a resolv.conf
pointing at an address nothing answered on, and no upstream for anything else.
Now the resolver keeps `no-resolv` (the documented loop — finding its own address in
resolv.conf and becoming its own upstream — stays impossible) and forwards to the same
two explicit upstreams; listens on mesh0 and 127.0.0.1, which systemd-resolved does not
hold; requires `mesh-addressing`, since its data is the mesh's addresses; and writes the
runtime's `dns` into daemon.json beside whatever the machine had (ADR 0102), at this
machine's own address — `${machine:address}`, new in the controller. The runtime is not
restarted for it: it reads the key at start, not on reload, and a restart stops every
container; on the machine this replaces the value is already there.
resolv-conf names the resolver alone, as the predecessor's file did; its placeholder second
line was a fallback nothing ever reached. resolved-split-dns follows the address. The
mesh's suffix as a local domain comes with the machines file, so a mesh name the resolver
does not know is refused here rather than asked upstream. mDNS is not carried: no module
does it and the design says mesh names are not multicast names.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Read against hal/modules/dnsmasq-app (hal dnsmasq-app conversion, hq 08-connectivity). Pairs with mesh-controller
convert/dnsmasq-from-hal, which adds${machine:address}and writeslocal=/<suffix>/into thenode-zonesfact — merge that first, or the dnsmasq module's runtime-dns file is refused at composition.What the predecessor does on a machine: dnsmasq answers every name — the mesh's own itself, the rest forwarded to 1.1.1.1 and 8.8.8.8 (its module's defaults); resolv.conf names it alone at 127.0.0.1; the container runtime's
dnsis the machine's tunnel address.What the module does now:
dnsmasq: keepsno-resolv(the documented loop stays impossible) and forwards to the same two explicit upstreams; listens onmesh0and127.0.0.1(not .53/.54, which systemd-resolved holds; .55 dropped — one address, the one every machine's resolv.conf already names);domain-needed,bogus-priv,bind-dynamic; requiresmesh-addressing; writes{"dns":["${machine:address}"]}into/etc/docker/daemon.json(ADR 0102), no runtime restart ordered — the runtime readsdnsat start, not on reload, and a restart stops every container; on the machine this replaces the value is already there.resolv-conf:nameserver 127.0.0.1alone plusoptions edns0, as the predecessor wrote; the placeholder second nameserver was a fallback nothing ever reached.resolved-split-dns: follows the address (DNS=127.0.0.1); still routes only the suffix, for a machine that keeps systemd-resolved in charge of the rest./etc/mesh-resolver/nodes.confis thenode-zonesfact the manifest already asked for; the deadmesh-resolver/resolver-dataconstants are removed in the controller. It now carrieslocal=/<suffix>/too.Not settled here (see the controller PR body): the predecessor's per-node
DNSMASQ_SPLIT_DNS/local-domain entries have no nox equivalent; a container on the runtime's default bridge on a converged node is filtered from port 53 (from: mesh);Domains=~internalin resolved-split-dns still hard-codes the default suffix.Tests: mesh-controller
internal/catalogue/resolver_manifests_test.goparses and composes these three manifests from this checkout;cmd/mesh-controllercomposes the resolver's machines file on a real mesh and again after a node leaves.Read against hal/modules/dnsmasq-app (hal dnsmasq-app conversion, hq 08-connectivity). On the machines it runs, the predecessor's dnsmasq answers every name: the mesh's own itself, the rest forwarded to 1.1.1.1 and 8.8.8.8, its module's defaults; resolv.conf names it alone at 127.0.0.1, and the container runtime's dns is the machine's tunnel address, so the host and every container resolve the world through it. The nox module forwarded nothing, listened on 127.0.0.55 — a convention of its own beside the one every machine already followed — and read a machines file that the module's `facts` already asks the mesh for, so taking it would have left an adopted machine with a resolv.conf pointing at an address nothing answered on, and no upstream for anything else. Now the resolver keeps `no-resolv` (the documented loop — finding its own address in resolv.conf and becoming its own upstream — stays impossible) and forwards to the same two explicit upstreams; listens on mesh0 and 127.0.0.1, which systemd-resolved does not hold; requires `mesh-addressing`, since its data is the mesh's addresses; and writes the runtime's `dns` into daemon.json beside whatever the machine had (ADR 0102), at this machine's own address — `${machine:address}`, new in the controller. The runtime is not restarted for it: it reads the key at start, not on reload, and a restart stops every container; on the machine this replaces the value is already there. resolv-conf names the resolver alone, as the predecessor's file did; its placeholder second line was a fallback nothing ever reached. resolved-split-dns follows the address. The mesh's suffix as a local domain comes with the machines file, so a mesh name the resolver does not know is refused here rather than asked upstream. mDNS is not carried: no module does it and the design says mesh names are not multicast names.4991c09c1fto3d81bf41c6