You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
tailscale/net/dns
Brad Fitzpatrick 88c2afd1e3 ipn/ipnlocal, net/dns*, util/cloudenv: specialize DNS config on Google Cloud
This does three things:

* If you're on GCP, it adds a *.internal DNS split route to the
  metadata server, so we never break GCP DNS names. This lets people
  have some Tailscale nodes on GCP and some not (e.g. laptops at home)
  without having to add a Tailnet-wide *.internal DNS route.
  If you already have such a route, though, it won't overwrite it.

* If the 100.100.100.100 DNS forwarder has nowhere to forward to,
  it forwards it to the GCP metadata IP, which forwards to 8.8.8.8.
  This means there are never errNoUpstreams ("upstream nameservers not set")
  errors on GCP due to e.g. mangled /etc/resolv.conf (GCP default VMs
  don't have systemd-resolved, so it's likely a DNS supremacy fight)

* makes the DNS fallback mechanism use the GCP metadata IP as a
  fallback before our hosted HTTP-based fallbacks

I created a default GCP VM from their web wizard. It has no
systemd-resolved.

I then made its /etc/resolv.conf be empty and deleted its GCP
hostnames in /etc/hosts.

I then logged in to a tailnet with no global DNS settings.

With this, tailscaled writes /etc/resolv.conf (direct mode, as no
systemd-resolved) and sets it to 100.100.100.100, which then has
regular DNS via the metadata IP and *.internal DNS via the metadata IP
as well. If the tailnet configures explicit DNS servers, those are used
instead, except for *.internal.

This also adds a new util/cloudenv package based on version/distro
where the cloud type is only detected once. We'll likely expand it in
the future for other clouds, doing variants of this change for other
popular cloud environments.

Fixes #4911

RELNOTES=Google Cloud DNS improvements

Change-Id: I19f3c2075983669b2b2c0f29a548da8de373c7cf
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>
4 years ago
..
publicdns net/dns/publicdns: add missing call to sync.Once.Do (#4410) 4 years ago
resolvconffile all: use strings.Cut even more 4 years ago
resolver ipn/ipnlocal, net/dns*, util/cloudenv: specialize DNS config on Google Cloud 4 years ago
config.go tailcfg,all: change structs to []*dnstype.Resolver 4 years ago
debian_resolvconf.go all: gofmt with Go 1.17 4 years ago
direct.go net/dns: ignore permission errors on Synology DSM7 for now 4 years ago
direct_test.go net/dns: require space after nameserver/search parsing resolv.conf 4 years ago
flush_default.go wgengine: flush DNS cache after major link change. 4 years ago
flush_windows.go wgengine: flush DNS cache after major link change. 4 years ago
ini.go all: gofmt with Go 1.17 4 years ago
ini_test.go all: gofmt -w -s (simplify) tests 4 years ago
manager.go net/dns{., resolver}: time out DNS queries after 10 seconds (#4690) 4 years ago
manager_darwin.go net/dns: add tailscaled-on-macOS DNS OSConfigurator 4 years ago
manager_default.go net/dns: add tailscaled-on-macOS DNS OSConfigurator 4 years ago
manager_freebsd.go net/dns: fall back to copy+delete/truncate if moving to/from /etc/resolv.conf fails. 4 years ago
manager_linux.go net/dns: add health check for particular broken-ish Linux DNS config 4 years ago
manager_linux_test.go all: use any instead of interface{} 4 years ago
manager_openbsd.go net/dns: teach OpenBSD's manager to talk to resolvd(8). (#2789) 4 years ago
manager_tcp_test.go net/dns, wgengine: implement DNS over TCP (#4598) 4 years ago
manager_test.go tailcfg,all: change structs to []*dnstype.Resolver 4 years ago
manager_windows.go net/dns: set appropriate Windows registry values to prevent it from sending DNS changes concerning our interface to AD domain controllers. 4 years ago
manager_windows_test.go net/dns: update Windows split DNS settings to work alongside other NRPT entries set by group policy. 4 years ago
nm.go all: use any instead of interface{} 4 years ago
noop.go net/dns: return error from NewOSManager, use it to initialize NM. 5 years ago
nrpt_windows.go net/dns: update Windows split DNS settings to work alongside other NRPT entries set by group policy. 4 years ago
openresolv.go all: gofmt with Go 1.17 4 years ago
osconfig.go net/dns: make debian_resolvconf correctly clear DNS configs. 5 years ago
registry_windows.go wgengine/router/dns: move to net/dns. 5 years ago
resolvconf-workaround.sh net/dns: also include 'tail' and 'base' files when fixing up resolv.conf. 5 years ago
resolvconf.go net/dns: exhaustively test DNS selection paths for linux. 4 years ago
resolvd.go net/dns/resolvconffile: unify three /etc/resolv.conf parsers into new package 4 years ago
resolved.go all: use any instead of interface{} 4 years ago
utf.go net/dns: detect and decode UTF-16 from wsl.exe earlier. 4 years ago
utf_test.go net/dns: detect and decode UTF-16 from wsl.exe earlier. 4 years ago
wsl_windows.go net/dns: fix checking for wrapped error when attempting to read wsl.conf for Windows WSL2 4 years ago