mesh/merge-gate pass: builds networkmanager, systemd-networkd, sent nowhere; no bus step; 4 wait(s) for a person; every machine composes with the change as…
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
mesh/delivery-group group feat/node-uplink-verbs delivered: every member is delivered
What a machine resolves through had no tool: the resolver file and who wrote it, and every link with its default route and the resolvers its manager knows. Each holder serves the same two node-uplink verbs; the reading is one text carried by both, held to it by a test, and only asking the manager for a link's names is each holder's own.
61 lines
4.0 KiB
JSON
61 lines
4.0 KiB
JSON
{
|
|
"module": "systemd-networkd",
|
|
"version": "1",
|
|
"upgrade": {
|
|
"policy": "record",
|
|
"why": "the machine's network: a build that breaks it can cut the machine off from the bus, and then neither the gate's rollback nor a push reaches it (hq ADR 0236)"
|
|
},
|
|
"slug": "networkd",
|
|
"requires": [
|
|
"wildcard-resolution"
|
|
],
|
|
"capabilities": [
|
|
"service-manager",
|
|
"uplink-systemd-networkd"
|
|
],
|
|
"claims": [
|
|
{
|
|
"name": "node-uplink",
|
|
"scope": "node"
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "tools",
|
|
"kind": "bundle",
|
|
"language": "go",
|
|
"system": "arch",
|
|
"from": "cmd/uplink-tools",
|
|
"binary": "uplink-tools",
|
|
"loads": [
|
|
"uplink-tools"
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"facts": {
|
|
"resolvers": {
|
|
"path": "/etc/resolv.conf",
|
|
"template": "# Managed by the mesh, and written by the module holding this machine's uplink:\n# the program that manages the machine's network would otherwise rewrite this\n# file on every change of network, so its holder is the one that writes it\n# (novox/hq ADR 0117, ADR 0223). Replaced on every push; edit nothing here.\n#\n# Every resolver of the mesh, by address, and nothing else (novox/hq ADR 0223) —\n# this machine's own first when it holds one, then the others by name. Each\n# answers the mesh's names from the same roster and forwards every other name, so\n# whichever answers first gives the one answer. There is no public resolver here:\n# a C library that asks every listed server at once and takes the first reply —\n# musl, so every Alpine container — took a public resolver's \"no such name\" for\n# a mesh name and failed. A machine that reaches none of these has no names until\n# it does. Containers copy these lines from their machine.\n{{range index .Holders \"mesh-dns-resolver\"}}nameserver {{.Address}}\n{{end}}options timeout:1 attempts:2 edns0\n"
|
|
}
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "config",
|
|
"type": "file",
|
|
"path": "/etc/systemd/network/00-mesh0.network",
|
|
"mode": "0644",
|
|
"content": "# Managed by the mesh (module systemd-networkd). Replaced on every push; edit\n# the catalogue instead.\n#\n# This machine's uplink is systemd-networkd's, and the mesh asks one thing of it\n# here (novox/hq ADR 0117): leave the private network's interface alone. mesh0\n# is the mesh's; the mesh brings it up and configures it itself. The mesh never\n# declares a link, an address, a route, a wireless network or its credentials,\n# nor a network file for any of this machine's own interfaces — those are\n# the operator's, and the link they make is the only channel the mesh reaches\n# this machine over.\n#\n# 00-: networkd applies the first .network file, in alphanumeric order across\n# every directory, that matches an interface, and ignores every later one even\n# if it matches too (systemd.network(5), [Match]). A catch-all of the operator's\n# — Name=*, Type=ether, a file with no [Match] at all — sorted before\n# this one would claim mesh0 first. 00 sorts before every numbered prefix the\n# man page recommends.\n#\n# Unmanaged=yes: \"no attempts are made to bring up or configure matching links,\n# equivalent to when there are no matching network files\" (systemd.network(5),\n# [Link], since 233). A match that ends the search, and does nothing else.\n#\n# No DNS setting, because none is needed: networkd never writes\n# /etc/resolv.conf. What it learns from a lease it hands only to\n# systemd-resolved, which the mesh does not run (novox/hq ADR 0196). So this\n# module declares the resolver file itself, beside this one, listing the\n# mesh's resolvers (novox/hq ADR 0223).\n#\n# The service is reloaded when this file changes, never restarted: a restart\n# drops the links networkd holds, this machine's channel to the mesh among them.\n[Match]\nName=mesh0\n\n[Link]\nUnmanaged=yes\n"
|
|
},
|
|
{
|
|
"id": "service",
|
|
"type": "service",
|
|
"unit": "systemd-networkd.service",
|
|
"reload-on": [
|
|
"config"
|
|
]
|
|
}
|
|
]
|
|
}
|