dns: fixed 1.1.1.1/8.8.8.8 lockdown + scoped mDNS, esphome sibling container
- deploy.conf: DNS_RESOLVERS, always 1.1.1.1/8.8.8.8, never a WAN's own DHCP/RA-provided servers (previously whatever Wapana handed out). - ap/99-van-router-dns.conf: global resolved config (fixed DNS, Domains=~., global MulticastDNS=yes — a prerequisite for any per-link mDNS to work at all, not just an on/off toggle). - failover/60-van-wan-dns: NM dispatcher that strips each WAN's DNS/search- domain and disables its mDNS via resolvectl on every connect/lease event (NM's own ipv4/ipv6.ignore-auto-dns can't be set as a config-file default — confirmed rejected as an unknown key — so this enforces it directly instead), retried over ~5s to beat NM's own async DNS commit. Also logs what each WAN advertised, never used, to /run/van-wan-dns/. - ap/21-van-br0.network: MulticastDNS=yes, scoped to the van's own LAN only — .local/mDNS now resolves for ESPHome and other LAN devices without leaking mDNS onto Wapana/Starlink/cellular. - dns/: ZeroTier-managed DNS (zt.wrede.pvt) made reproducible — installed the official zerotier-systemd-manager package (verified against upstream checksums), additive to the above so *.zt.wrede.pvt keeps resolving over the overlay independent of WAN. - ha/esphome.container: ESPHome dashboard as a sibling Podman Quadlet to Home Assistant, same host-network/config-volume pattern. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
5d88e1b30c
commit
8efb8dba5f
@@ -24,3 +24,9 @@ STARLINK_IFACE=enxd8ec5eeb3512
|
||||
|
||||
# Cellular modem USB vendor ID (Quectel EC25-AF)
|
||||
MODEM_USB_VENDOR=2c7c
|
||||
|
||||
# Fixed upstream DNS resolvers — this router always uses these, never a WAN's
|
||||
# own DHCP/RA-provided servers (NetworkManager is told to ignore those
|
||||
# entirely; see ap/van-wan-dns.conf + ap/99-van-router-dns.conf). Keeps
|
||||
# resolution identical on Wapana, Starlink, or cellular.
|
||||
DNS_RESOLVERS="1.1.1.1 8.8.8.8"
|
||||
|
||||
Reference in New Issue
Block a user