-
Notifications
You must be signed in to change notification settings - Fork 219
libnetwork/resolvconf: add new KeepHostSearches/Options #2445
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
Using one KeepHostServers that controls the override of nameservers, search domains and options is not good enough. With netavark 1.15 we dropped the dns.podman search domain[1] as this always overwrote the host search domains which was not correct. However that in turn caused a new issue[2] that a container name might now get resolved to a search domain from the host first. To fix that we either need to revert the dns.podman change or add the ndots:0 option in resolv.conf. Whatever we end up doing we will need one of KeepHostSearches or KeepHostOptions in podman to populate resolv.conf correctly so that we don't overwrite the host domains/options but still can overwrite the nameservers as we want to force aardvark-dns only as nameserver so resolvers cannot bypass it. [1] containers/netavark#1214 [2] containers/podman#26198 Signed-off-by: Paul Holzinger <[email protected]>
Reviewer's GuideIntroduces two new parameters to control preserving host DNS search domains and options when generating resolv.conf, updates the builder logic to respect these flags, and extends unit tests to validate the new behavior. File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hey @Luap99 - I've reviewed your changes and they look great!
Here's what I looked at during the review
- 🟡 General issues: 1 issue found
- 🟢 Security: all looks good
- 🟢 Testing: all looks good
- 🟢 Complexity: all looks good
- 🟢 Documentation: all looks good
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: Luap99, sourcery-ai[bot] The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
LGTM |
Using one KeepHostServers that controls the override of nameservers, search domains and options is not good enough.
With netavark 1.15 we dropped the dns.podman search domain[1] as this always overwrote the host search domains which was not correct. However that in turn caused a new issue[2] that a container name might now get resolved to a search domain from the host first.
To fix that we either need to revert the dns.podman change or add the ndots:0 option in resolv.conf. Whatever we end up doing we will need one of KeepHostSearches or KeepHostOptions in podman to populate resolv.conf correctly so that we don't overwrite the host domains/options but still can overwrite the nameservers as we want to force aardvark-dns only as nameserver so resolvers cannot bypass it.
[1] containers/netavark#1214
[2] containers/podman#26198
Summary by Sourcery
Add dedicated flags to preserve host search domains and DNS options when generating resolv.conf and update the generation logic and tests accordingly.
New Features:
Enhancements:
Tests: