{ "module": "resolved-split-dns", "version": "1", "requires": ["wildcard-resolution"], "claims": [{"name": "the-resolver-configuration", "scope": "node"}], "resources": [ {"id": "drop-in", "type": "directory", "path": "/etc/systemd/resolved.conf.d", "mode": "0755"}, {"id": "route", "type": "file", "path": "/etc/systemd/resolved.conf.d/mesh.conf", "mode": "0644", "content": "# Managed by the mesh.\n#\n# **Only the mesh's names.** The tilde makes this a routing domain rather than a\n# search domain: queries under it go to the resolver below, and everything else\n# keeps going wherever this machine already sent it. A resolver that took over\n# all of DNS would be this module claiming the machine's whole network, which\n# is not what it says it claims.\n#\n# 127.0.0.54 is where the mesh's resolver answers on every machine — a name the\n# mesh chose, so this file needs to know nothing about this particular one.\n[Resolve]\nDNS=127.0.0.54\nDomains=~internal\n"}, {"id": "resolved", "type": "service", "unit": "systemd-resolved.service", "state": "running", "boot": "enabled", "restart-on": ["route"]} ] }