fix(3088): stop dnsmasq shadowing hive DNS with the host's /etc/hosts
localHostsEntry's 127.0.0.1 rows leak into the address= answers dnsmasq gives agent containers now that it runs on the host, sending every agent back to itself instead of the bridge IP.
This commit is contained in:
parent
9932e7babd
commit
50605851f4
1 changed files with 14 additions and 0 deletions
|
|
@ -27,6 +27,20 @@
|
||||||
];
|
];
|
||||||
bind-interfaces = true;
|
bind-interfaces = true;
|
||||||
port = 53;
|
port = 53;
|
||||||
|
# Authoritative for the hive domain via the `address` rules below —
|
||||||
|
# must not fall back to the host's /etc/hosts. dnsmasq reads
|
||||||
|
# /etc/hosts by default, and `gateway.localHostsEntry` populates it
|
||||||
|
# with 127.0.0.1 for every hive name (host-side dev convenience,
|
||||||
|
# see default.nix). Since #3088 moved dnsmasq onto the host, that
|
||||||
|
# file is now the *same* /etc/hosts dnsmasq reads for agent queries
|
||||||
|
# — its entries win over `address=`, so every agent resolves the
|
||||||
|
# hive's own domains back to itself (127.0.0.1 in its own netns)
|
||||||
|
# instead of the bridge IP, and can't reach the forge, matrix, or
|
||||||
|
# dashboard at all. `no-hosts = true` keeps the authoritative
|
||||||
|
# `address=` rules in charge for containers while leaving
|
||||||
|
# `networking.hosts` (the actual /etc/hosts entries) untouched for
|
||||||
|
# host-side browsing.
|
||||||
|
no-hosts = true;
|
||||||
# Hive authoritative records — answer queries for the hive domain
|
# Hive authoritative records — answer queries for the hive domain
|
||||||
# + its sub-domains with the bridge IP, where nginx is reachable
|
# + its sub-domains with the bridge IP, where nginx is reachable
|
||||||
# from every container netns.
|
# from every container netns.
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue