a container may name its resolvers and its own address #26

Merged
jschoubben merged 1 commits from feat/a-container-may-name-its-resolver-and-its-address into main 2026-09-25 21:48:45 +00:00
Owner

Found live, blocking mailu's Phase-2 cutover: 2024.06's admin refuses to serve behind a non-DNSSEC-validating resolver, the runtime's forwarder (127.0.0.11) validates nothing, and the declaration language had no words to point a module's containers at its own validating unbound.

Two container fields, both handed to the runtime verbatim: dns (the resolvers it asks) and ip (its static address on its user-defined network — existing for exactly one shape: a container others must reach before name resolution works, i.e. the resolver itself). Both take only addresses and are refused on arrival otherwise, since a name would reach the runtime verbatim and fail at create — after the old container was already gone.

Tested: run args carry --dns/--ip; validation refuses a named resolver, an address without a network, and accepts the well-formed pair. Full suite green. The controller passes container resource maps through untouched, so this is host-only.

Found live, blocking mailu's Phase-2 cutover: 2024.06's admin refuses to serve behind a non-DNSSEC-validating resolver, the runtime's forwarder (127.0.0.11) validates nothing, and the declaration language had no words to point a module's containers at its own validating unbound. Two container fields, both handed to the runtime verbatim: `dns` (the resolvers it asks) and `ip` (its static address on its user-defined network — existing for exactly one shape: a container others must reach *before* name resolution works, i.e. the resolver itself). Both take only addresses and are refused on arrival otherwise, since a name would reach the runtime verbatim and fail at create — after the old container was already gone. Tested: run args carry `--dns`/`--ip`; validation refuses a named resolver, an address without a network, and accepts the well-formed pair. Full suite green. The controller passes container resource maps through untouched, so this is host-only.
jschoubben added 1 commit 2026-09-25 21:48:39 +00:00
Mailu's 2024.06 admin refuses to serve behind a resolver that does not
validate DNSSEC, and the runtime's own forwarder (127.0.0.11) validates
nothing — so a module shipping its own validating resolver had a
resolver nothing could be pointed at. Found live, blocking a cutover:
the admin sat unhealthy, submission answered 454, and the declaration
language had no words for the fix.

Two fields on a container, both handed to the runtime verbatim: dns —
the resolvers it asks — and ip, its static address on its user-defined
network, which exists for exactly one shape: a container others must
reach before name resolution works, the resolver itself being the case
that forced it. Both take only addresses and are refused on arrival
otherwise — a name here would reach the runtime verbatim and be refused
at create, after the old container was already gone.
jschoubben merged commit 93caf26aed into main 2026-09-25 21:48:45 +00:00
jschoubben deleted branch feat/a-container-may-name-its-resolver-and-its-address 2026-09-25 21:48:45 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-host#26