Archived
fix(tailscale-router): stop dnsmasq from intercepting host DNS queries
Check NixOS configurations / eval-hosts (pull_request) Successful in 10m30s
Check NixOS configurations / eval-hosts (pull_request) Successful in 10m30s
NixOS's dnsmasq module defaults resolveLocalQueries to true, which adds 127.0.0.1 to networking.nameservers and binds dnsmasq to listen-address=127.0.0.1. This made the host route all its own DNS through dnsmasq, which had no-resolv=true and no upstream for anything outside the tailnet domain — so every non-tailscale DNS query from the host itself (including SSSD resolving the IPA server FQDN after the IPA client module was added) failed. Setting resolveLocalQueries=false limits dnsmasq to its intended role: a forwarding proxy reachable on the LAN interface for IPA's conditional forwarder. The host uses domainControllerIp directly (already set in networking.nameservers in host.nix). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -19,6 +19,14 @@
|
|||||||
# tailnet-specific subdomain (vars.tailnetDomain) instead.
|
# tailnet-specific subdomain (vars.tailnetDomain) instead.
|
||||||
services.dnsmasq = {
|
services.dnsmasq = {
|
||||||
enable = true;
|
enable = true;
|
||||||
|
# NixOS's dnsmasq module defaults resolveLocalQueries to true, which adds
|
||||||
|
# 127.0.0.1 to networking.nameservers and makes dnsmasq bind to
|
||||||
|
# listen-address=127.0.0.1. This instance is not the host's local
|
||||||
|
# resolver — it only serves IPA's conditional forwarder for tailnet names.
|
||||||
|
# The host uses domainControllerIp directly (networking.nameservers in
|
||||||
|
# host.nix). Without this, all host DNS goes through dnsmasq, which has
|
||||||
|
# no upstream for general queries (no-resolv=true), breaking resolution.
|
||||||
|
resolveLocalQueries = false;
|
||||||
settings = {
|
settings = {
|
||||||
# Listen only on the LAN interface — not tailscale0 or loopback.
|
# Listen only on the LAN interface — not tailscale0 or loopback.
|
||||||
# bind-interfaces prevents dnsmasq from binding to 0.0.0.0 and
|
# bind-interfaces prevents dnsmasq from binding to 0.0.0.0 and
|
||||||
|
|||||||
Reference in New Issue
Block a user