Give a container the names, rather than a resolver to ask
The commit before this said "told where to resolve names" and passed --dns, which is not what it ended up doing. This is that correction: a container is given the names themselves, written into its own hosts file by the runtime. The reason for the change is the decision the mesh already made about names — a file rather than a resolver, because it works on every runtime, needs no package and has no failure mode of its own. Passing a resolver address would have required a resolver to exist, which at that point none did. A resolver is coming, for the case a file genuinely cannot express: a service named under a machine, postgres.novox.internal, where the wildcard cannot be enumerated in advance. When it arrives it will need this field back under its own name. It is not being kept in the meantime — a field nothing fills is a field nobody can trust, and the vocabulary is asserted by a count for exactly that reason.
This commit is contained in:
@@ -328,18 +328,22 @@ type Container struct {
|
||||
Ports []string `json:"ports,omitempty"`
|
||||
Volumes []string `json:"volumes,omitempty"`
|
||||
Args []string `json:"args,omitempty"`
|
||||
// Nameservers this container resolves through.
|
||||
// Names this container can reach, as `name:address`.
|
||||
//
|
||||
// **Because a container does not inherit the machine's names.** It gets its own `/etc/hosts`
|
||||
// holding its own hostname, and a runtime rewrites `resolv.conf` — so every internal name the
|
||||
// mesh wrote for this machine is invisible to the thing the machine is running. That was hit
|
||||
// for real: a database client on one node could not resolve another node, on a mesh where
|
||||
// both names were correct and present.
|
||||
// holding only its own hostname, so every internal name the mesh wrote for this machine is
|
||||
// invisible to the thing the machine is running. That was hit for real: a database client on
|
||||
// one node could not resolve another node, on a mesh where both names were correct and
|
||||
// present on both machines.
|
||||
//
|
||||
// Set by the mesh rather than by a module: which resolver a machine has is a fact about the
|
||||
// machine, and a module that named one would be a module that only runs where somebody put
|
||||
// that resolver.
|
||||
Nameservers []string `json:"nameservers,omitempty"`
|
||||
// **A file rather than a resolver, which is the decision the mesh already made about names**
|
||||
// and this extends rather than overturns: it works on every runtime, needs no package, and
|
||||
// has no failure mode of its own. A resolver becomes necessary when names are wanted that are
|
||||
// not one-per-node — service names, wildcards — and that is still not true.
|
||||
//
|
||||
// Set by the mesh, not by a module: which machines exist is a fact about the mesh, and a
|
||||
// module that listed them would be a module that goes stale when one joins.
|
||||
Hosts []string `json:"hosts,omitempty"`
|
||||
|
||||
// Network is the container's network, passed to the runtime unchanged.
|
||||
//
|
||||
|
||||
Reference in New Issue
Block a user