- dnsmasq holds mesh-dns-resolver: provides wildcard-resolution mesh-wide, forwards every declared zone (zones fact), listens on the private address and loopback only, reads no hosts file and no operator's files, and no longer writes the container runtime's dns. - resolv-conf names the mesh's resolver by address, then 1.1.1.1, timeout 1, one attempt; it now holds the runtime's live-restore, which dnsmasq held and every node needs. - resolved-split-dns routes the suffix to the mesh's resolver by address, not 127.0.0.1. - hosts: new module holding node-hosts-file — the machine's own lines in its block of /etc/hosts, the operator's lines kept, changed by entries/add/remove through sudo -n.
41 lines
1.8 KiB
JSON
41 lines
1.8 KiB
JSON
{
|
|
"module": "resolv-conf",
|
|
"version": "1",
|
|
"slug": "resolv",
|
|
"requires": [
|
|
"wildcard-resolution"
|
|
],
|
|
"claims": [
|
|
{
|
|
"name": "node-resolver-config",
|
|
"scope": "node"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "resolv",
|
|
"type": "file",
|
|
"path": "/etc/resolv.conf",
|
|
"mode": "0644",
|
|
"content": "# Managed by the mesh.\n#\n# For a machine where nothing else owns this file. On one where systemd-resolved\n# or NetworkManager does, assign that module instead — this one and those claim\n# the same thing, so the mesh refuses the pair rather than letting them take\n# turns overwriting each other, which is the failure this claim exists to stop.\n#\n# The mesh's one resolver first (novox/hq ADR 0194, 0196), by address — a machine\n# cannot resolve the name of the thing it resolves names with. It answers the\n# mesh's names itself and forwards every other name. A public resolver second,\n# asked only when the first does not answer at all — its machine or the tunnel\n# down, a captive portal holding the tunnel back — so public names keep\n# resolving then. An answer from the first, \"no such name\" included, is final,\n# so a mesh name is never asked of the public one while the mesh's answers. One\n# second and one attempt, so the wait before the fallback is short. Containers\n# copy these two lines from their machine.\nnameserver ${bound:wildcard-resolution:address}\nnameserver 1.1.1.1\noptions timeout:1 attempts:1 edns0\n"
|
|
},
|
|
{
|
|
"id": "runtime-config",
|
|
"type": "file",
|
|
"path": "/etc/docker/daemon.json",
|
|
"mode": "0644",
|
|
"into": "json",
|
|
"content": "{\"live-restore\": true}\n"
|
|
},
|
|
{
|
|
"id": "runtime",
|
|
"type": "service",
|
|
"unit": "docker.service",
|
|
"state": "running",
|
|
"reload-on": [
|
|
"runtime-config"
|
|
]
|
|
}
|
|
]
|
|
}
|