Re: systemd-resolved fallback DNS servers: usability vs. GDPR

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Dnia Mon, Feb 22, 2021 at 10:58:09AM +0100, Tadej Janež napisał(a):
> Hi,
> 
> I would like to question the decision that was made by systemd
> maintainers to remove the fallback DNS server list:
> https://src.fedoraproject.org/rpms/systemd/c/14b2fafb3688a4170a9c15235d1c3feb7ddeaf9d
> 
> And then backported to F33:
> https://src.fedoraproject.org/rpms/systemd/c/ed795fb1fc9a2c20ebcac34bdf7e7c7ae17322a2?branch=f33
> 
> On F33, this actually breaks a working vanilla cloud instance by
> removing the fallback DNS server list in a systemd upgrade, effectively
> leaving the system with no DNS servers configured.
> 
> I described this in more detail here:
> https://lists.fedoraproject.org/archives/list/cloud@xxxxxxxxxxxxxxxxxxxxxxx/thread/72MRKIFGPMFGBS7XJ5T5I23NVDXXWVGR/


  Let's be careful not to go in circles.  It seems you have "broken"
configuration - no DNS servers are provided to the cloud image. So none
are configured.  Previously, systemd package provided a fallback DNS
resolvers for that case. Then it stopped doing that.

  Now the circles - the change in systemd package was the outcome of
discussion here on -devel list. In this discussion some people had a
position "if I do not provide DNS servers, I don't want DNS to work".
Which is resonable and expected in high-control situations.
  Providing the workaround again would go against wishes of those people.
>From their perspective your non-resolving cloud image is exactly as you
want it. As you configured it.

> 
> Possible solutions that come to mind:
> 1) Use different defaults for different Fedora editions, e.g. container
> and cloud images include the fallback DNS servers list while
> workstation (and similar) images don't.
> 2) Pick a reputable DNS resolver that preserves users' privacy and
> doesn't log anything and configure it as a fallback DNS server.

3) Configure DNS resolvers if you want to use DNS.
Or dig deeper: why cloud-init disabled DNS on your installation?

-- 
Tomasz Torcz           “(…) today's high-end is tomorrow's embedded processor.”
tomek@xxxxxxxxxxxxxx                      — Mitchell Blank on LKML
_______________________________________________
devel mailing list -- devel@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to devel-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel@xxxxxxxxxxxxxxxxxxxxxxx
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure




[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Fedora Announce]     [Fedora Users]     [Fedora Kernel]     [Fedora Testing]     [Fedora Formulas]     [Fedora PHP Devel]     [Kernel Development]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite News]

  Powered by Linux