Thirty modules the mesh builds, provisions and runs, as manifests — one per module, flat under modules/. They were in mesh-control/examples/, which framed the mesh's real modules as illustrations of a control-plane package; they are neither examples nor the control plane's. The engine that reads them stays in mesh-control; the data lives here, consumed as a build source. Answers the tier-4 question novox/hq ADR 0030 left open — where the catalogue lives — in favour of one flat repository, which the drop of domain grouping (seats, claims and tags instead) makes the right shape. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
19 lines
1.2 KiB
JSON
19 lines
1.2 KiB
JSON
{
|
|
"module": "resolved-split-dns",
|
|
"version": "1",
|
|
|
|
"requires": ["wildcard-resolution"],
|
|
"claims": [{"name": "the-resolver-configuration", "scope": "node"}],
|
|
|
|
"resources": [
|
|
{"id": "drop-in", "type": "directory", "path": "/etc/systemd/resolved.conf.d", "mode": "0755"},
|
|
|
|
{"id": "route", "type": "file",
|
|
"path": "/etc/systemd/resolved.conf.d/mesh.conf", "mode": "0644",
|
|
"content": "# Managed by the mesh.\n#\n# **Only the mesh's names.** The tilde makes this a routing domain rather than a\n# search domain: queries under it go to the resolver below, and everything else\n# keeps going wherever this machine already sent it. A resolver that took over\n# all of DNS would be this module claiming the machine's whole network, which\n# is not what it says it claims.\n#\n# 127.0.0.55 is where the mesh's resolver answers on every machine — a fixed\n# address, so this file needs to know nothing about this particular machine.\n# systemd-resolved holds .53 and .54, which is why it is neither.\n[Resolve]\nDNS=127.0.0.55\nDomains=~internal\n"},
|
|
|
|
{"id": "resolved", "type": "service", "unit": "systemd-resolved.service",
|
|
"state": "running", "boot": "enabled", "restart-on": ["route"]}
|
|
]
|
|
}
|