A container can be told where to resolve names

A container does not inherit the machine's names. It gets its own /etc/hosts
holding its own hostname, and a runtime rewrites resolv.conf — so every
internal name the mesh wrote for that machine is invisible to what the machine
is running.

That was hit for real, in the lab: a database client on one node could not
resolve another node, on a mesh where both names were correct and present on
both machines. It was worked around by resolving on the host and passing an
address, which is the kind of workaround that should not be needed twice.

A field on an existing shape, not a ninth shape — the vocabulary is still the
eight the count asserts.

Per container rather than by editing the machine's resolver configuration: that
file belongs to something else on most machines, and a host that edited it
would be fighting whatever owns it on every boot — the fault this host exists
to avoid, in the place it would be hardest to see.

A container told nothing is run exactly as before. Most containers should
resolve whatever the machine resolves, and passing an empty flag would be a
change of behaviour dressed up as a default.
This commit is contained in:
2026-08-31 11:09:49 +02:00
parent 8fcfa88fe0
commit 0e2b288bb6
3 changed files with 92 additions and 0 deletions
+13
View File
@@ -328,6 +328,19 @@ type Container struct {
Ports []string `json:"ports,omitempty"`
Volumes []string `json:"volumes,omitempty"`
Args []string `json:"args,omitempty"`
// Nameservers this container resolves through.
//
// **Because a container does not inherit the machine's names.** It gets its own `/etc/hosts`
// holding its own hostname, and a runtime rewrites `resolv.conf` — so every internal name the
// mesh wrote for this machine is invisible to the thing the machine is running. That was hit
// for real: a database client on one node could not resolve another node, on a mesh where
// both names were correct and present.
//
// Set by the mesh rather than by a module: which resolver a machine has is a fact about the
// machine, and a module that named one would be a module that only runs where somebody put
// that resolver.
Nameservers []string `json:"nameservers,omitempty"`
// Network is the container's network, passed to the runtime unchanged.
//
// Needed because the control plane must reach the store and the broker on the machine it was