a container may name its resolvers and its own address
Mailu's 2024.06 admin refuses to serve behind a resolver that does not validate DNSSEC, and the runtime's own forwarder (127.0.0.11) validates nothing — so a module shipping its own validating resolver had a resolver nothing could be pointed at. Found live, blocking a cutover: the admin sat unhealthy, submission answered 454, and the declaration language had no words for the fix. Two fields on a container, both handed to the runtime verbatim: dns — the resolvers it asks — and ip, its static address on its user-defined network, which exists for exactly one shape: a container others must reach before name resolution works, the resolver itself being the case that forced it. Both take only addresses and are refused on arrival otherwise — a name here would reach the runtime verbatim and be refused at create, after the old container was already gone.
This commit is contained in:
@@ -1508,6 +1508,12 @@ func applyContainer(ctx context.Context, r *declaration.Container, run Runner,
|
||||
if r.Network != "" {
|
||||
args = append(args, "--network", r.Network)
|
||||
}
|
||||
for _, d := range r.Dns {
|
||||
args = append(args, "--dns", d)
|
||||
}
|
||||
if r.IP != "" {
|
||||
args = append(args, "--ip", r.IP)
|
||||
}
|
||||
args = append(args,
|
||||
"--label", specLabel+"="+want, "--label", idLabel+"="+r.ID)
|
||||
for _, k := range sortedKeys(r.Env) {
|
||||
|
||||
Reference in New Issue
Block a user