9a4961d94b450f40a36f1f54d3be9c7331a3f9ac
Add an architecture analysis for the tension between Tailscale's default resolv.conf management (100.100.100.100) and the managed LAN-resolver resolv.conf (.252/.253). Documents a key finding from live-network probing: knel.net device records only resolve via the Tailscale MagicDNS path; querying the LAN DNS servers directly returns NXDOMAIN because their knel.net zone is stale (SOA serial 2025-06-23). Lays out four options (Tailscale-owned, LAN-pinned, split DNS, Tailscale-pushes-LAN-resolvers) with pros/cons, recommends leaving DNS to Tailscale in the short term (since wazuh/postfix/syslog depend on knel.net names that only resolve there) and fixing the Technitium/Pi-hole knel.net zone before pinning the LAN resolvers. Confirms the NTP (LAN-IP) change is safe regardless. Flags that the managed-resolv.conf change will be overwritten by Tailscale and would break knel.net resolution if it ever sticks. 🤖 Generated with [Crush](https://github.com/charmassociates/crush) Assisted-by: GLM-5 via Crush <crush@charm.land>
KNEL FetchApply
Repo Issues
https://projects.knownelement.com/project/reachableceo-vptechnicaloperations/timeline
Repo Discussion
https://community.turnsys.com/c/chieftechnologyandproductofficer/26
Repo discription
Known Element Enterprises (the entity serving as the TSYS Group management company) (through it’s executive leader, the COO) provides core IT/back office systems/services/support on a hands off/fully delegated authortity basis to the CCO and the orgs/members.
One of those functions is the provisoning of Linux servers. This repository is the Infrastructure As Code (IAC) repository for TSYS.
In the future it will be used via FetchApply https://github.com/P5vc/fetch-apply
Usage
git clone this repo cd FetchApply/ProjectCode bash SetupNewSystem.sh