musl takes the first reply from any listed nameserver, so a public fallback beside the mesh's resolver answered NXDOMAIN for mesh names in every Alpine container (hq ADR 0223). The fix is two mesh resolvers and no public one, which needs mesh-dns-resolver held on two machines: a seat can now be replicated, each holder recorded by 'seat <name> --add', checkClaims accepts every holder on record and still refuses a second holder of any other mesh seat, a holder answers its own requirement, and a roster fact gives each replicated seat's holders, this machine first, so resolv-conf can list them. Migration 0062 keys a holding by seat and assignment.
15 lines
1.0 KiB
SQL
15 lines
1.0 KiB
SQL
-- A replicated seat has several holders on record (novox/hq ADR 0223).
|
|
--
|
|
-- 0039 recorded one holder per seat, keyed by the seat: a handover replaced the row, so the seat was
|
|
-- never without a holder in between. The mesh's resolver is now held on more than one machine, each
|
|
-- answering the same names, and each of those holders is recorded — added by `seat <name> --add`,
|
|
-- never by being assigned. So a holding is keyed by the seat and the assignment holding it.
|
|
--
|
|
-- Nothing else changes. A handover (`seat <name> --to`) still leaves exactly one row, replacing every
|
|
-- holder in one transaction; whether a seat may have more than one is the seat's compiled definition,
|
|
-- judged by the controller before a row is added, and a store holding two for any other seat is
|
|
-- refused at resolution, naming the seat. Every existing row is one per seat, so it satisfies the new
|
|
-- key as it stands.
|
|
alter table seat_holding drop constraint seat_holding_pkey;
|
|
alter table seat_holding add primary key (seat, node, module);
|