Tell the resolver the machines, not the names the mesh merely serves #53

Merged
jschoubben merged 1 commits from fix/the-resolver-is-told-machines-not-routes into main 2026-09-23 23:32:22 +00:00
Owner

Found composing the resolver's first assignment on a live machine and reading the plan before pushing it. The file the mesh would have handed the resolver named three "machines", two of which were module public names with the mesh's suffix appended — names nobody will ever ask for.

The control plane hands a resolution one map of names and it holds both kinds: the machines, and every name the mesh was told to route to whichever machine serves it (ADR 0066). A container's hosts file wants all of it. The resolver's zones want only the machines, and the difference matters because of the line above them — told the mesh's suffix is its own, the resolver answers authoritatively for everything under it and forwards none of it. So the invented names sit beside the real ones looking exactly as real.

Now the rendering carries the two sets separately and each fact is handed the one it is true of: the hosts file keeps every name, the zones take the machines. One test pins both halves together so neither can drift into the other.

Note for the reviewer: my first attempt discriminated by "does the name already carry the suffix", which an existing test correctly rejected — the map may legitimately be keyed by bare machine names. Splitting the sets at the source is the fix.

19 packages green with a database; gofmt clean. hq issue 111.

Found composing the resolver's first assignment on a live machine and reading the plan before pushing it. The file the mesh would have handed the resolver named three "machines", two of which were module **public names** with the mesh's suffix appended — names nobody will ever ask for. The control plane hands a resolution one map of names and it holds both kinds: the machines, and every name the mesh was told to route to whichever machine serves it (ADR 0066). A container's hosts file wants all of it. The resolver's zones want only the machines, and the difference matters because of the line above them — told the mesh's suffix is its own, the resolver answers authoritatively for everything under it and forwards none of it. So the invented names sit beside the real ones looking exactly as real. Now the rendering carries the two sets separately and each fact is handed the one it is true of: the hosts file keeps every name, the zones take the machines. One test pins both halves together so neither can drift into the other. Note for the reviewer: my first attempt discriminated by "does the name already carry the suffix", which an existing test correctly rejected — the map may legitimately be keyed by bare machine names. Splitting the sets at the source is the fix. 19 packages green with a database; gofmt clean. hq issue 111.
jschoubben added 1 commit 2026-09-23 23:32:17 +00:00
The map the control plane hands a resolution holds both: the machines, and every name
the mesh was told to route to whichever machine serves it. A container's hosts wants all
of it, so a routed name resolves to the proxy. A resolver's zones want only the machines:
told the mesh's suffix is its own it answers authoritatively for everything under it and
forwards none of it, so a routed name with the suffix appended — drive.example.test.internal
— is a name nobody will ever ask for, standing beside the machines and looking as real.

Found composing the resolver's first assignment on a live machine, before pushing it.
hq issue 111.
jschoubben merged commit 6090953843 into main 2026-09-23 23:32:22 +00:00
jschoubben deleted branch fix/the-resolver-is-told-machines-not-routes 2026-09-23 23:32:22 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#53