Give a container the names, rather than a resolver to ask

The commit before this said "told where to resolve names" and passed --dns,
which is not what it ended up doing. This is that correction: a container is
given the names themselves, written into its own hosts file by the runtime.

The reason for the change is the decision the mesh already made about names — a
file rather than a resolver, because it works on every runtime, needs no
package and has no failure mode of its own. Passing a resolver address would
have required a resolver to exist, which at that point none did.

A resolver is coming, for the case a file genuinely cannot express: a service
named under a machine, postgres.novox.internal, where the wildcard cannot be
enumerated in advance. When it arrives it will need this field back under its
own name. It is not being kept in the meantime — a field nothing fills is a
field nobody can trust, and the vocabulary is asserted by a count for exactly
that reason.
This commit is contained in:
2026-08-31 12:05:52 +02:00
parent 0e2b288bb6
commit c3d6f240fe
3 changed files with 27 additions and 25 deletions
+6 -6
View File
@@ -812,12 +812,12 @@ func applyContainer(ctx context.Context, r *declaration.Container, run Runner) (
for _, v := range r.Volumes {
args = append(args, "--volume", v)
}
for _, n := range r.Nameservers {
// Per container rather than by changing the machine's resolver configuration. That file
// belongs to something else on most machines, and a host that edited it would be fighting
// whatever owns it on every boot — the fault this host exists to avoid, in the one place
// it would be hardest to see.
args = append(args, "--dns", n)
for _, h := range r.Hosts {
// Written into the container's own hosts file by the runtime. Per container rather than
// by editing the machine's resolver configuration: that file belongs to something else on
// most machines, and a host that edited it would be fighting whatever owns it on every
// boot — the fault this host exists to avoid, in the place it would be hardest to see.
args = append(args, "--add-host", h)
}
args = append(args, r.Image)
args = append(args, r.Args...)
+8 -10
View File
@@ -1231,7 +1231,7 @@ func TestAFailedActionStopsWhatFollows(t *testing.T) {
// `resolv.conf` — so every internal name the mesh wrote for the machine is invisible to what the
// machine is running. That was hit for real: a database client on one node could not resolve
// another node, on a mesh where both names were correct and present on both machines.
func TestAContainerIsToldWhichResolverToUse(t *testing.T) {
func TestAContainerIsGivenTheMeshsNames(t *testing.T) {
var ran []string
run := func(_ context.Context, name string, args ...string) (string, error) {
if name != "docker" {
@@ -1250,25 +1250,23 @@ func TestAContainerIsToldWhichResolverToUse(t *testing.T) {
}
d := parseTrusted(t, `{"declaration":1,"resources":[
{"id":"app","type":"container","name":"app","image":"`+pinned+`",
"nameservers":["10.42.0.1"]}
"hosts":["anchor.internal:10.42.0.1"]}
]}`)
_, _, _ = Apply(context.Background(), archHost(t), d, store.State{}, store.OriginCarried, run, nil, nil)
var told bool
for i, a := range ran {
if a == "--dns" && i+1 < len(ran) && ran[i+1] == "10.42.0.1" {
if a == "--add-host" && i+1 < len(ran) && ran[i+1] == "anchor.internal:10.42.0.1" {
told = true
}
}
if !told {
t.Fatalf("the container was not told where to resolve names: %v", ran)
t.Fatalf("the container cannot reach another machine by name: %v", ran)
}
}
// And a container that was told nothing is run exactly as before: most containers resolve
// whatever the machine resolves, and passing an empty flag would be a change of behaviour
// dressed as a default.
func TestAContainerToldNothingIsRunAsBefore(t *testing.T) {
// And a container given no names is run exactly as before.
func TestAContainerGivenNoNamesIsRunAsBefore(t *testing.T) {
var ran []string
run := func(_ context.Context, name string, args ...string) (string, error) {
if name != "docker" {
@@ -1291,8 +1289,8 @@ func TestAContainerToldNothingIsRunAsBefore(t *testing.T) {
_, _, _ = Apply(context.Background(), archHost(t), d, store.State{}, store.OriginCarried, run, nil, nil)
for _, a := range ran {
if a == "--dns" {
t.Fatalf("a container that was told nothing was given a resolver anyway: %v", ran)
if a == "--add-host" {
t.Fatalf("a container given no names was given some anyway: %v", ran)
}
}
}