- dnsmasq holds mesh-dns-resolver: provides wildcard-resolution mesh-wide, forwards every declared zone (zones fact), listens on the private address and loopback only, reads no hosts file and no operator's files, and no longer writes the container runtime's dns. - resolv-conf names the mesh's resolver by address, then 1.1.1.1, timeout 1, one attempt; it now holds the runtime's live-restore, which dnsmasq held and every node needs. - resolved-split-dns routes the suffix to the mesh's resolver by address, not 127.0.0.1. - hosts: new module holding node-hosts-file — the machine's own lines in its block of /etc/hosts, the operator's lines kept, changed by entries/add/remove through sudo -n.
42 lines
998 B
JSON
42 lines
998 B
JSON
{
|
|
"module": "hosts",
|
|
"version": "1",
|
|
"claims": [
|
|
{
|
|
"name": "node-hosts-file",
|
|
"scope": "node",
|
|
"serves": [
|
|
"entries",
|
|
"add",
|
|
"remove"
|
|
]
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "own",
|
|
"type": "file",
|
|
"path": "/etc/hosts",
|
|
"mode": "0644",
|
|
"into": "block",
|
|
"at": "start",
|
|
"content": "# The machine's own names (module hosts, novox/hq ADR 0199). Every line outside this block is the\n# operator's: kept across every push, changed through the node-hosts-file verbs add and remove, and\n# given back when this module goes. The mesh's names are not here: the mesh's resolver answers them.\n127.0.0.1\tlocalhost\n::1\tlocalhost\n"
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "tools",
|
|
"kind": "bundle",
|
|
"language": "typescript",
|
|
"entrypoints": [
|
|
"tools/index.js"
|
|
],
|
|
"loads": [
|
|
"tools/index.js"
|
|
]
|
|
}
|
|
]
|
|
}
|
|
}
|