Route every host built by this project through the new pfv-netinfra-01 (192.168.3.252) / pfv-netinfra-02 (192.168.3.253) pair for both name resolution and time, with automatic failover. - NTP: replace the single pfv-netboot.knel.net upstream with both netinfra servers (iburst) so time sync survives either one failing. - DNS: add a managed static /etc/resolv.conf (new ConfigFiles/Resolv/). The repo previously had no resolver configuration at all. Both servers are listed so glibc falls through to the secondary on failure. - DHCP: request domain-name-servers/domain-search/ntp-servers and supersede them to the netinfra pair, so a DHCP renew can't silently revert to whatever the DHCP server advertises. - SetupNewSystem.sh: deploy resolv.conf (robustly replacing any systemd-resolved/NetworkManager symlink) and add pfv-netinfra to the NTP-server self-exclusion guard so those boxes don't client off themselves. LAN IPs are used throughout (not the knel.net hostnames) because those hostnames resolve to Tailscale CGNAT addresses, not the LAN addresses, and NTP must come up before DNS. Add a validation test asserting the config is present and both servers actually answer DNS and NTP queries. 🤖 Generated with [Crush](https://github.com/charmassociates/crush) Assisted-by: GLM-5 via Crush <crush@charm.land>
12 lines
505 B
Plaintext
12 lines
505 B
Plaintext
# Managed by KNELServerBuild — do not edit; changes will be overwritten.
|
|
#
|
|
# Redundant recursive DNS via pfv-netinfra-01/02 (Technitium + Pi-hole).
|
|
# IPs are used (required: nameserver directives must be addresses, and the
|
|
# knel.net name for these hosts resolves to a Tailscale CGNAT address rather
|
|
# than the LAN address). If the primary is unreachable, glibc's resolver
|
|
# automatically falls through to the secondary.
|
|
domain knel.net
|
|
search knel.net
|
|
nameserver 192.168.3.252
|
|
nameserver 192.168.3.253
|