fix(3088): stop dnsmasq shadowing hive DNS with the host's /etc/hosts

localHostsEntry's 127.0.0.1 rows leak into the address= answers dnsmasq
gives agent containers now that it runs on the host, sending every
agent back to itself instead of the bridge IP.
This commit is contained in:
müde 2026-08-11 23:25:28 +02:00
commit 50605851f4

View file

@ -27,6 +27,20 @@
];
bind-interfaces = true;
port = 53;
# Authoritative for the hive domain via the `address` rules below —
# must not fall back to the host's /etc/hosts. dnsmasq reads
# /etc/hosts by default, and `gateway.localHostsEntry` populates it
# with 127.0.0.1 for every hive name (host-side dev convenience,
# see default.nix). Since #3088 moved dnsmasq onto the host, that
# file is now the *same* /etc/hosts dnsmasq reads for agent queries
# — its entries win over `address=`, so every agent resolves the
# hive's own domains back to itself (127.0.0.1 in its own netns)
# instead of the bridge IP, and can't reach the forge, matrix, or
# dashboard at all. `no-hosts = true` keeps the authoritative
# `address=` rules in charge for containers while leaving
# `networking.hosts` (the actual /etc/hosts entries) untouched for
# host-side browsing.
no-hosts = true;
# Hive authoritative records — answer queries for the hive domain
# + its sub-domains with the bridge IP, where nginx is reachable
# from every container netns.