An identity is `mesh_<node>_<slug-or-name>` and a backend keeps 20 characters (an S3 access key). Overflow makes a module unresolvable, and this catalogue was finding it one module at a time, on a raise: route-proxy on novox is 22, home-assistant on ace is 23. Two found by hand where a sweep would have found eighteen. So the whole catalogue was swept instead, against the longest node name the mesh actually has (`shanks`, six characters) rather than against the node each module happens to sit on today — a module is assigned somewhere, and where is not a property of the manifest. That leaves eight characters for the identity source, and eighteen modules were over it. Slugs added, chosen to stay greppable in a provider's user list: anthropic-consumer claude openai-consumer openai anthropic-manager anthmgr portainer portain audit-logger audit public-acme pubacme bookshelf books qbittorrent qbt cloudflare-dns cfdns resolv-conf resolv confluence confl resolved-split-dns splitdns home-assistant hass route-proxy rproxy invoicing invoice verdaccio verdacc mosquitto mosq nextcloud ncloud A slug changes the login the mesh mints, so a module already provisioned under its full name is re-minted under the slug and its old login withdrawn — which is the provisioner's ordinary business, but it is a change, not a no-op. Checked with the real parser: every one of the 66 manifests through `catalogue.ParseManifest`, and every module's `CheckIdentity` against all four node names. 0 problems, where the same check over the parent commit reports 44.
20 lines
1.2 KiB
JSON
20 lines
1.2 KiB
JSON
{
|
|
"module": "resolved-split-dns",
|
|
"version": "1",
|
|
"slug": "splitdns",
|
|
|
|
"requires": ["wildcard-resolution"],
|
|
"claims": [{"name": "the-resolver-configuration", "scope": "node"}],
|
|
|
|
"resources": [
|
|
{"id": "drop-in", "type": "directory", "path": "/etc/systemd/resolved.conf.d", "mode": "0755"},
|
|
|
|
{"id": "route", "type": "file",
|
|
"path": "/etc/systemd/resolved.conf.d/mesh.conf", "mode": "0644",
|
|
"content": "# Managed by the mesh.\n#\n# **Only the mesh's names.** The tilde makes this a routing domain rather than a\n# search domain: queries under it go to the resolver below, and everything else\n# keeps going wherever this machine already sent it. A resolver that took over\n# all of DNS would be this module claiming the machine's whole network, which\n# is not what it says it claims.\n#\n# 127.0.0.55 is where the mesh's resolver answers on every machine — a fixed\n# address, so this file needs to know nothing about this particular machine.\n# systemd-resolved holds .53 and .54, which is why it is neither.\n[Resolve]\nDNS=127.0.0.55\nDomains=~internal\n"},
|
|
|
|
{"id": "resolved", "type": "service", "unit": "systemd-resolved.service",
|
|
"state": "running", "boot": "enabled", "restart-on": ["route"]}
|
|
]
|
|
}
|