Files
mesh-catalog/modules/forticlient/module.json
T
jochen 35d7421d54
mesh/merge-gate fail: builds forticlient, new: modules/systemd-resolved → g14, shanks; no bus step; a manifest the change touches fails the module check: m…
mesh/repo-check fail: its merge-check.sh failed: long-running resources without health: 70
mesh/delivery superseded: a newer head of the same pull request
forticlient: hand the client's resolver file to the machine's own resolver (hq ADR 0247)
FortiClient writes /etc/resolv.conf itself on connect and never tells
resolved a link's DNS. The module now requires split-dns and runs an
adapter as root that reads the client's servers and domains from its write,
routes them over the client's tunnel through the resolver's socket on the
machine, takes the write so the resolver's file is back at once, and takes
the route away when the tunnel goes. Nothing of it crosses the bus.
2026-10-07 21:30:26 +02:00

58 lines
1.2 KiB
JSON

{
"module": "forticlient",
"version": "1",
"upgrade": {
"policy": "record",
"why": "its adapter routes the company's domains on the machine a person works on: a build that breaks it cuts the person off from work names until a person pushes the next (hq ADR 0236, ADR 0247)"
},
"capabilities": [
"service-manager"
],
"requires": [
"x11-display",
"split-dns"
],
"tools": [
"forticlient_status",
"forticlient_restart",
"forticlient_check"
],
"resources": [
{
"id": "scheduler",
"type": "service",
"unit": "forticlient.service",
"state": "running",
"boot": "enabled"
},
{
"id": "split-dns",
"type": "process",
"name": "forticlient-split-dns",
"artifact": "tools",
"run": [
"./forticlient-tools",
"split-dns"
],
"health": {
"kind": "unit"
}
}
],
"build": {
"artifacts": [
{
"name": "tools",
"kind": "bundle",
"language": "go",
"system": "arch",
"from": "cmd/forticlient-tools",
"binary": "forticlient-tools",
"loads": [
"forticlient-tools"
]
}
]
}
}