musl asks every nameserver at once and takes the first reply, so a public resolver's NXDOMAIN for a mesh name beat the mesh's answer in every Alpine container (hq ADR 0223). resolv-conf now renders /etc/resolv.conf from the holders of mesh-dns-resolver, this machine first when it holds one; dnsmasq's comments say the seat may have several holders.
21 lines
1.3 KiB
JSON
21 lines
1.3 KiB
JSON
{
|
|
"module": "resolv-conf",
|
|
"version": "1",
|
|
"slug": "resolv",
|
|
"requires": [
|
|
"wildcard-resolution"
|
|
],
|
|
"claims": [
|
|
{
|
|
"name": "node-resolver-config",
|
|
"scope": "node"
|
|
}
|
|
],
|
|
"facts": {
|
|
"resolvers": {
|
|
"path": "/etc/resolv.conf",
|
|
"template": "# Managed by the mesh.\n#\n# The machine's network manager is told to leave this file alone by the module\n# holding its uplink, which the mesh requires beside this one (novox/hq ADR 0117,\n# 0220): without it, the first change of network would rewrite the file.\n#\n# Every resolver of the mesh, by address, and nothing else (novox/hq ADR 0223) —\n# this machine's own first when it holds one, then the others by name. Each\n# answers the mesh's names from the same roster and forwards every other name, so\n# whichever answers first gives the one answer. There is no public resolver here:\n# a C library that asks every listed server at once and takes the first reply —\n# musl, so every Alpine container — took a public resolver's \"no such name\" for\n# a mesh name and failed. A machine that reaches none of these has no names until\n# it does. Containers copy these lines from their machine.\n{{range index .Holders \"mesh-dns-resolver\"}}nameserver {{.Address}}\n{{end}}options timeout:1 attempts:2 edns0\n"
|
|
}
|
|
}
|
|
}
|