FortiClient writes /etc/resolv.conf itself on connect and never tells resolved a link's DNS. The module now requires split-dns and runs an adapter as root that reads the client's servers and domains from its write, routes them over the client's tunnel through the resolver's socket on the machine, takes the write so the resolver's file is back at once, and takes the route away when the tunnel goes. Nothing of it crosses the bus.
58 lines
1.2 KiB
JSON
58 lines
1.2 KiB
JSON
{
|
|
"module": "forticlient",
|
|
"version": "1",
|
|
"upgrade": {
|
|
"policy": "record",
|
|
"why": "its adapter routes the company's domains on the machine a person works on: a build that breaks it cuts the person off from work names until a person pushes the next (hq ADR 0236, ADR 0247)"
|
|
},
|
|
"capabilities": [
|
|
"service-manager"
|
|
],
|
|
"requires": [
|
|
"x11-display",
|
|
"split-dns"
|
|
],
|
|
"tools": [
|
|
"forticlient_status",
|
|
"forticlient_restart",
|
|
"forticlient_check"
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "scheduler",
|
|
"type": "service",
|
|
"unit": "forticlient.service",
|
|
"state": "running",
|
|
"boot": "enabled"
|
|
},
|
|
{
|
|
"id": "split-dns",
|
|
"type": "process",
|
|
"name": "forticlient-split-dns",
|
|
"artifact": "tools",
|
|
"run": [
|
|
"./forticlient-tools",
|
|
"split-dns"
|
|
],
|
|
"health": {
|
|
"kind": "unit"
|
|
}
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "tools",
|
|
"kind": "bundle",
|
|
"language": "go",
|
|
"system": "arch",
|
|
"from": "cmd/forticlient-tools",
|
|
"binary": "forticlient-tools",
|
|
"loads": [
|
|
"forticlient-tools"
|
|
]
|
|
}
|
|
]
|
|
}
|
|
}
|