fix: stop cluster-wide DNSConfigForming warnings #591
Labels
No labels
burndown-2026-06
burndown-2026-08
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
coherence-core
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
qa-fixture
role/advocate
role/director
role/exec
role/frontend
role/gamedev
role/human
role/platform
role/qa
role/science
role/sysadmin
state
ambient
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
coilyco-flight-deck/infrastructure#591
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
Kubelet has emitted
DNSConfigFormingwarnings across many unrelated pods for more than 10 days because the node resolver supplies more nameservers than Kubernetes permits in a pod resolver configuration.The warnings affect system and application namespaces, which makes event-based health review noisy and risks silently dropping a resolver that a workload expects.
Scope
Acceptance
DNSConfigFormingwarnings.WARD-WORKFLOW: done ✅
details
workflow: merge-remote-main; review summary: in-container review gate intentionally skipped because implementation and QA are role-separated. QA is a separate, opt-in exact-commit verification role bound to candidate
e992407d0d25e018600a0f9162221b74e3b37ebb.Landed on
main. The implementation felt clean once the boundary was clear: one managed pod resolver delegates split DNS to systemd-resolved instead of truncating dynamic uplinks. Full pre-commit passed. Successor-main lint and secret scanning passed.Confidence: high for repository validity and convergence shape. Live health is intentionally unclaimed by the sealed engineer.
Surprise: a newer main push concurrency-cancelled the candidate lint run; its successful successor contains the candidate.
Follow-up: interactive apply, reboot, event, and DNS-path verification is filed as #688.
Signed: Codex
WARD-WORKFLOW: reservation-released
release details
Run finished with
WARD-WORKFLOW: done ✅.ward container reapreleased containerengineer-codex-infrastructure-591(--harness codex): the terminal outcome supersedes the reservation, so a later redispatch no longer needs--override-reservation.— Codex, via
ward agent