- dnsmasq holds mesh-dns-resolver: provides wildcard-resolution mesh-wide, forwards every declared zone (zones fact), listens on the private address and loopback only, reads no hosts file and no operator's files, and no longer writes the container runtime's dns. - resolv-conf names the mesh's resolver by address, then 1.1.1.1, timeout 1, one attempt; it now holds the runtime's live-restore, which dnsmasq held and every node needs. - resolved-split-dns routes the suffix to the mesh's resolver by address, not 127.0.0.1. - hosts: new module holding node-hosts-file — the machine's own lines in its block of /etc/hosts, the operator's lines kept, changed by entries/add/remove through sudo -n.
40 lines
1.5 KiB
JSON
40 lines
1.5 KiB
JSON
{
|
|
"module": "resolved-split-dns",
|
|
"version": "1",
|
|
"slug": "splitdns",
|
|
"requires": [
|
|
"wildcard-resolution"
|
|
],
|
|
"claims": [
|
|
{
|
|
"name": "node-resolver-config",
|
|
"scope": "node"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "drop-in",
|
|
"type": "directory",
|
|
"path": "/etc/systemd/resolved.conf.d",
|
|
"mode": "0755"
|
|
},
|
|
{
|
|
"id": "route",
|
|
"type": "file",
|
|
"path": "/etc/systemd/resolved.conf.d/mesh.conf",
|
|
"mode": "0644",
|
|
"content": "# Managed by the mesh.\n#\n# **Only the mesh's names.** The tilde makes this a routing domain rather than a\n# search domain: queries under it go to the resolver below, and everything else\n# keeps going wherever this machine already sent it. A resolver that took over\n# all of DNS would be this module claiming the machine's whole network, which\n# is not what it says it claims. The mesh's resolver can forward the rest too;\n# this module is for a machine that wants systemd-resolved to stay in charge of\n# that, and only lends it the mesh's suffix.\n#\n# The mesh's one resolver (novox/hq ADR 0194), by its private address — a\n# machine cannot resolve the name of the thing it resolves names with.\n[Resolve]\nDNS=${bound:wildcard-resolution:address}\nDomains=~internal\n"
|
|
},
|
|
{
|
|
"id": "resolved",
|
|
"type": "service",
|
|
"unit": "systemd-resolved.service",
|
|
"state": "running",
|
|
"boot": "enabled",
|
|
"restart-on": [
|
|
"route"
|
|
]
|
|
}
|
|
]
|
|
}
|