Ten manifests claim mesh-* names now. What they PROVIDE is unchanged: gitea still provides git and npm-package-registry, and a consumer requires the interface, not the seat.
40 lines
1.6 KiB
JSON
40 lines
1.6 KiB
JSON
{
|
|
"module": "resolved-split-dns",
|
|
"version": "1",
|
|
"slug": "splitdns",
|
|
"requires": [
|
|
"wildcard-resolution"
|
|
],
|
|
"claims": [
|
|
{
|
|
"name": "mesh-resolver-configuration",
|
|
"scope": "node"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "drop-in",
|
|
"type": "directory",
|
|
"path": "/etc/systemd/resolved.conf.d",
|
|
"mode": "0755"
|
|
},
|
|
{
|
|
"id": "route",
|
|
"type": "file",
|
|
"path": "/etc/systemd/resolved.conf.d/mesh.conf",
|
|
"mode": "0644",
|
|
"content": "# Managed by the mesh.\n#\n# **Only the mesh's names.** The tilde makes this a routing domain rather than a\n# search domain: queries under it go to the resolver below, and everything else\n# keeps going wherever this machine already sent it. A resolver that took over\n# all of DNS would be this module claiming the machine's whole network, which\n# is not what it says it claims. The mesh's resolver can forward the rest too;\n# this module is for a machine that wants systemd-resolved to stay in charge of\n# that, and only lends it the mesh's suffix.\n#\n# 127.0.0.1 is where the mesh's resolver answers on every machine \u2014 a fixed\n# address, so this file needs to know nothing about this particular machine.\n# systemd-resolved holds .53 and .54 itself, which is why the resolver is on\n# neither, and why the two coexist here.\n[Resolve]\nDNS=127.0.0.1\nDomains=~internal\n"
|
|
},
|
|
{
|
|
"id": "resolved",
|
|
"type": "service",
|
|
"unit": "systemd-resolved.service",
|
|
"state": "running",
|
|
"boot": "enabled",
|
|
"restart-on": [
|
|
"route"
|
|
]
|
|
}
|
|
]
|
|
}
|