{ "module": "dnsmasq", "version": "1", "requires": ["resolver-data"], "provides": ["wildcard-resolution"], "claims": [{"name": "the-dns-port", "scope": "node"}], "listens": [ {"port": 53, "protocol": "udp", "from": "mesh", "why": "names under every machine in this mesh, for this machine and what it runs"} ], "resources": [ {"id": "package", "type": "package", "package": "dnsmasq"}, {"id": "config", "type": "file", "path": "/etc/dnsmasq.conf", "mode": "0644", "content": "# Managed by the mesh. dnsmasq's own defaults are replaced whole rather than\n# patched, because this module owns the file and a patch would leave whatever\n# was there before to be discovered later.\n\n# What the mesh computed: one wildcard per machine, its name and everything\n# under it. Rewritten whenever a machine joins or leaves, which is why the\n# service below reflects it.\nconf-file=/etc/mesh-resolver/nodes.conf\n\n# Where it answers. Both are names the mesh chose, so this file needs to know\n# nothing about this particular machine:\n#\n# mesh0 the private network, so anything on it — including a container\n# on this machine — can ask.\n# 127.0.0.54 this machine's own use. Not 127.0.0.1 and not 127.0.0.53:\n# the first is where everything else expects a resolver, and the\n# second is systemd-resolved's. Taking either would be this\n# module claiming something it did not say it claims.\n#\n# bind-dynamic rather than bind-interfaces: mesh0 does not exist until the\n# machine is on the private network, and binding an interface that is not there\n# yet fails to start rather than waiting for it.\nbind-dynamic\ninterface=mesh0\nlisten-address=127.0.0.54\n\n# It answers for the mesh and forwards nothing it was not asked about. Names\n# outside the mesh are somebody else's business, and a resolver that answered\n# them would be this module taking over more than it claims.\ndomain-needed\nbogus-priv\n"}, {"id": "service", "type": "service", "unit": "dnsmasq.service", "state": "running", "boot": "enabled", "restart-on": ["config", "mesh-resolver.nodes"]} ] }