Add TOML configuration for default DNS nameservers, search, options - #1614

Open
0xMH wants to merge 3 commits into
apple:mainfrom
0xMH:fix/1449-dns-defaults
Open

Add TOML configuration for default DNS nameservers, search, options#1614
0xMH wants to merge 3 commits into
apple:mainfrom
0xMH:fix/1449-dns-defaults

Conversation

@0xMH

@0xMH0xMH commented May 28, 2026

Copy link
Copy Markdown
Contributor

Type of Change

  • New feature

Motivation and Context

Closes#1449. Adds default values for --dns, --dns-search, --dns-option, and --dns-domain to the [dns] section of ~/.config/container/config.toml, so users hitting macOS mDNSResponder conflicts can set the workaround once instead of repeating it on every invocation. Depends on the merged TOML configuration introduced by #1425.

Defaults are read by container run, container build, and container builder start via a shared Utility.dnsConfiguration(from:defaults:) helper. CLI flags take precedence; --no-dns still disables DNS. Two pre-existing bugs in the build path were fixed to make the feature work end-to-end: BuildCommand was forwarding only dnsNameservers to the builder (now forwards all four DNS fields), and BuilderStart's dnsChanged check only compared the first non-empty field (now compares all four).

Testing

  • Tested locally
  • Added/updated tests
  • Added/updated docs

}

final public class DNSConfig: Codable, Sendable {
public static let defaultNameservers: [String] = []

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Today there is a subtle difference between what the default DNS settings are for container aka the apiserver itself, which would determine the hostname resolution (aka the A record) for a given container on the host, and the DNS settings for setting up the resolv.conf in a container. I think we should maintain this distinction. There could be scenarios where a user does not want the default DNS domain on the host to necessarily match the default DNS domain that the container application uses in the container itself.

I think we should add a new field on the ContainerConfig type that has the default DNS settings for running a container.

Essentially we'd end up with something like this in the TOML:

[dns] <-------- default DNS settings for the APIServer
domain = "test"
[container.dns] <----------- default DNS settings for containers server = "8.8.8.8"
domain = "foo"
search = ["foo", "test"]
options = ["haha"]

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, good insight. I removed that extra builder startup call.

@0xMH
0xMHforce-pushed the fix/1449-dns-defaults branch 2 times, most recently from 6af7693 to b010238CompareMay 31, 2026 22:56
@0xMH
0xMH requested a review from katiewasnothereJune 1, 2026 18:45
@github-actions

Copy link
Copy Markdown

Code Coverage

TierLine Coverage
Unit34.55%
Integration19.69%
Combined53.62%

@0xMH
0xMHforce-pushed the fix/1449-dns-defaults branch from b010238 to 3eb0a7eCompareJune 2, 2026 17:26
@0xMH
0xMHforce-pushed the fix/1449-dns-defaults branch from 3eb0a7e to 46bd18bCompareJune 3, 2026 23:29
@0xMH

0xMH commented Jun 3, 2026

Copy link
Copy Markdown
ContributorAuthor

Thanks for the review, @katiewasnothere. Happy to iterate further if anything else needs addressing.

@katiewasnotherekatiewasnothere added this to the 2026-06 milestone Jun 3, 2026
@katiewasnothere

Copy link
Copy Markdown
Contributor

Hi @0xMH thank you for all the work you've done on this change! We are planning to make a new release of the container package some time in the next week and we want to hold off on merging this change until then.

@am-saksham

Copy link
Copy Markdown

Hi @0xMH and @katiewasnothere! First, thanks for the great work figuring out the core logic for this.

I noticed this PR has been stalled since the June release and has picked up some merge conflicts. I also saw that a couple of newer PRs for #1449 were opened recently, but they seem to have missed the [dns] vs [container.dns] architectural requirement that Katie pointed out above.

@0xMH, if you are currently swamped with other things, would you mind if I pull your branch, resolve the conflicts against main, and open a fresh PR to get this over the finish line? I will carry over your commits and make sure to include a Co-authored-by tag so you keep full credit for your work.

Let me know if that sounds good!

@0xMH

0xMH commented Jul 5, 2026

Copy link
Copy Markdown
ContributorAuthor

Thanks for the offer! but no need since I'm waiting for the green flag to continue and rebase and prepare for the merge.

@am-saksham

Copy link
Copy Markdown

Awesome, sounds good! Looking forward to seeing it merged. Let me know if you end up needing a hand later on!

@jgloganjglogan removed this from the 2026-06 milestone Jul 7, 2026
@katiewasnothere

Copy link
Copy Markdown
Contributor

@0xMH Really sorry for the delay here, we've been swamped. I'd love to get this in for this sprint (which ends at the end of August). Could you rebase your PR? I will take another pass through the code. Thank you for your work here!

- `192.168.*.*`
- `172.16.*.*` through `172.31.*.*`
- The host ends with the machine's default container DNS domain (as defined in `DNSConfig.defaultDomain`, located [here](../Sources/ContainerPersistence/ContainerSystemConfig.swift))
- The host ends with the machine's configured internal DNS domain from `[dns].domain`

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could we add a link to the reference doc here instead?

public static func dnsConfiguration(
from flags: Flags.DNS,
defaults: ContainerDNSConfig,
hostDomainFallback: String? = nil

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What is this for?

Comment on lines +155 to +157
public let nameservers: [String]
public let searchDomains: [String]
public let options: [String]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think about making these optionals instead of empty arrays?


public let cpus: Int
public let memory: MemorySize
public let dns: ContainerDNSConfig

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think about making this an optional as well?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Request]: system property for default --dns.

4 participants

@0xMH@katiewasnothere@am-saksham@jglogan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Add TOML configuration for default DNS nameservers, search, options - #1614

Open
0xMH wants to merge 3 commits into
apple:mainfrom
0xMH:fix/1449-dns-defaults
Open

Add TOML configuration for default DNS nameservers, search, options#1614
0xMH wants to merge 3 commits into
apple:mainfrom
0xMH:fix/1449-dns-defaults

Conversation

@0xMH

@0xMH0xMH commented May 28, 2026

Copy link
Copy Markdown
Contributor

Type of Change

  • New feature

Motivation and Context

Closes#1449. Adds default values for --dns, --dns-search, --dns-option, and --dns-domain to the [dns] section of ~/.config/container/config.toml, so users hitting macOS mDNSResponder conflicts can set the workaround once instead of repeating it on every invocation. Depends on the merged TOML configuration introduced by #1425.

Defaults are read by container run, container build, and container builder start via a shared Utility.dnsConfiguration(from:defaults:) helper. CLI flags take precedence; --no-dns still disables DNS. Two pre-existing bugs in the build path were fixed to make the feature work end-to-end: BuildCommand was forwarding only dnsNameservers to the builder (now forwards all four DNS fields), and BuilderStart's dnsChanged check only compared the first non-empty field (now compares all four).

Testing

  • Tested locally
  • Added/updated tests
  • Added/updated docs

}

final public class DNSConfig: Codable, Sendable {
public static let defaultNameservers: [String] = []

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Today there is a subtle difference between what the default DNS settings are for container aka the apiserver itself, which would determine the hostname resolution (aka the A record) for a given container on the host, and the DNS settings for setting up the resolv.conf in a container. I think we should maintain this distinction. There could be scenarios where a user does not want the default DNS domain on the host to necessarily match the default DNS domain that the container application uses in the container itself.

I think we should add a new field on the ContainerConfig type that has the default DNS settings for running a container.

Essentially we'd end up with something like this in the TOML:

[dns] <-------- default DNS settings for the APIServer
domain = "test"
[container.dns] <----------- default DNS settings for containers server = "8.8.8.8"
domain = "foo"
search = ["foo", "test"]
options = ["haha"]

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, good insight. I removed that extra builder startup call.

@0xMH
0xMHforce-pushed the fix/1449-dns-defaults branch 2 times, most recently from 6af7693 to b010238CompareMay 31, 2026 22:56
@0xMH
0xMH requested a review from katiewasnothereJune 1, 2026 18:45
@github-actions

Copy link
Copy Markdown

Code Coverage

TierLine Coverage
Unit34.55%
Integration19.69%
Combined53.62%

@0xMH
0xMHforce-pushed the fix/1449-dns-defaults branch from b010238 to 3eb0a7eCompareJune 2, 2026 17:26
@0xMH
0xMHforce-pushed the fix/1449-dns-defaults branch from 3eb0a7e to 46bd18bCompareJune 3, 2026 23:29
@0xMH

0xMH commented Jun 3, 2026

Copy link
Copy Markdown
ContributorAuthor

Thanks for the review, @katiewasnothere. Happy to iterate further if anything else needs addressing.

@katiewasnotherekatiewasnothere added this to the 2026-06 milestone Jun 3, 2026
@katiewasnothere

Copy link
Copy Markdown
Contributor

Hi @0xMH thank you for all the work you've done on this change! We are planning to make a new release of the container package some time in the next week and we want to hold off on merging this change until then.

@am-saksham

Copy link
Copy Markdown

Hi @0xMH and @katiewasnothere! First, thanks for the great work figuring out the core logic for this.

I noticed this PR has been stalled since the June release and has picked up some merge conflicts. I also saw that a couple of newer PRs for #1449 were opened recently, but they seem to have missed the [dns] vs [container.dns] architectural requirement that Katie pointed out above.

@0xMH, if you are currently swamped with other things, would you mind if I pull your branch, resolve the conflicts against main, and open a fresh PR to get this over the finish line? I will carry over your commits and make sure to include a Co-authored-by tag so you keep full credit for your work.

Let me know if that sounds good!

@0xMH

0xMH commented Jul 5, 2026

Copy link
Copy Markdown
ContributorAuthor

Thanks for the offer! but no need since I'm waiting for the green flag to continue and rebase and prepare for the merge.

@am-saksham

Copy link
Copy Markdown

Awesome, sounds good! Looking forward to seeing it merged. Let me know if you end up needing a hand later on!

@jgloganjglogan removed this from the 2026-06 milestone Jul 7, 2026
@katiewasnothere

Copy link
Copy Markdown
Contributor

@0xMH Really sorry for the delay here, we've been swamped. I'd love to get this in for this sprint (which ends at the end of August). Could you rebase your PR? I will take another pass through the code. Thank you for your work here!

- `192.168.*.*`
- `172.16.*.*` through `172.31.*.*`
- The host ends with the machine's default container DNS domain (as defined in `DNSConfig.defaultDomain`, located [here](../Sources/ContainerPersistence/ContainerSystemConfig.swift))
- The host ends with the machine's configured internal DNS domain from `[dns].domain`

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could we add a link to the reference doc here instead?

public static func dnsConfiguration(
from flags: Flags.DNS,
defaults: ContainerDNSConfig,
hostDomainFallback: String? = nil

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What is this for?

Comment on lines +155 to +157
public let nameservers: [String]
public let searchDomains: [String]
public let options: [String]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think about making these optionals instead of empty arrays?


public let cpus: Int
public let memory: MemorySize
public let dns: ContainerDNSConfig

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think about making this an optional as well?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Request]: system property for default --dns.

4 participants

@0xMH@katiewasnothere@am-saksham@jglogan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add TOML configuration for default DNS nameservers, search, options - #1614

Open
0xMH wants to merge 3 commits into
apple:mainfrom
0xMH:fix/1449-dns-defaults
Open

Add TOML configuration for default DNS nameservers, search, options#1614
0xMH wants to merge 3 commits into
apple:mainfrom
0xMH:fix/1449-dns-defaults

Conversation

@0xMH

@0xMH0xMH commented May 28, 2026

Copy link
Copy Markdown
Contributor

Type of Change

  • New feature

Motivation and Context

Closes#1449. Adds default values for --dns, --dns-search, --dns-option, and --dns-domain to the [dns] section of ~/.config/container/config.toml, so users hitting macOS mDNSResponder conflicts can set the workaround once instead of repeating it on every invocation. Depends on the merged TOML configuration introduced by #1425.

Defaults are read by container run, container build, and container builder start via a shared Utility.dnsConfiguration(from:defaults:) helper. CLI flags take precedence; --no-dns still disables DNS. Two pre-existing bugs in the build path were fixed to make the feature work end-to-end: BuildCommand was forwarding only dnsNameservers to the builder (now forwards all four DNS fields), and BuilderStart's dnsChanged check only compared the first non-empty field (now compares all four).

Testing

  • Tested locally
  • Added/updated tests
  • Added/updated docs

}

final public class DNSConfig: Codable, Sendable {
public static let defaultNameservers: [String] = []

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Today there is a subtle difference between what the default DNS settings are for container aka the apiserver itself, which would determine the hostname resolution (aka the A record) for a given container on the host, and the DNS settings for setting up the resolv.conf in a container. I think we should maintain this distinction. There could be scenarios where a user does not want the default DNS domain on the host to necessarily match the default DNS domain that the container application uses in the container itself.

I think we should add a new field on the ContainerConfig type that has the default DNS settings for running a container.

Essentially we'd end up with something like this in the TOML:

[dns] <-------- default DNS settings for the APIServer
domain = "test"
[container.dns] <----------- default DNS settings for containers server = "8.8.8.8"
domain = "foo"
search = ["foo", "test"]
options = ["haha"]

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, good insight. I removed that extra builder startup call.

@0xMH
0xMHforce-pushed the fix/1449-dns-defaults branch 2 times, most recently from 6af7693 to b010238CompareMay 31, 2026 22:56
@0xMH
0xMH requested a review from katiewasnothereJune 1, 2026 18:45
@github-actions

Copy link
Copy Markdown

Code Coverage

TierLine Coverage
Unit34.55%
Integration19.69%
Combined53.62%

@0xMH
0xMHforce-pushed the fix/1449-dns-defaults branch from b010238 to 3eb0a7eCompareJune 2, 2026 17:26
@0xMH
0xMHforce-pushed the fix/1449-dns-defaults branch from 3eb0a7e to 46bd18bCompareJune 3, 2026 23:29
@0xMH

0xMH commented Jun 3, 2026

Copy link
Copy Markdown
ContributorAuthor

Thanks for the review, @katiewasnothere. Happy to iterate further if anything else needs addressing.

@katiewasnotherekatiewasnothere added this to the 2026-06 milestone Jun 3, 2026
@katiewasnothere

Copy link
Copy Markdown
Contributor

Hi @0xMH thank you for all the work you've done on this change! We are planning to make a new release of the container package some time in the next week and we want to hold off on merging this change until then.

@am-saksham

Copy link
Copy Markdown

Hi @0xMH and @katiewasnothere! First, thanks for the great work figuring out the core logic for this.

I noticed this PR has been stalled since the June release and has picked up some merge conflicts. I also saw that a couple of newer PRs for #1449 were opened recently, but they seem to have missed the [dns] vs [container.dns] architectural requirement that Katie pointed out above.

@0xMH, if you are currently swamped with other things, would you mind if I pull your branch, resolve the conflicts against main, and open a fresh PR to get this over the finish line? I will carry over your commits and make sure to include a Co-authored-by tag so you keep full credit for your work.

Let me know if that sounds good!

@0xMH

0xMH commented Jul 5, 2026

Copy link
Copy Markdown
ContributorAuthor

Thanks for the offer! but no need since I'm waiting for the green flag to continue and rebase and prepare for the merge.

@am-saksham

Copy link
Copy Markdown

Awesome, sounds good! Looking forward to seeing it merged. Let me know if you end up needing a hand later on!

@jgloganjglogan removed this from the 2026-06 milestone Jul 7, 2026
@katiewasnothere

Copy link
Copy Markdown
Contributor

@0xMH Really sorry for the delay here, we've been swamped. I'd love to get this in for this sprint (which ends at the end of August). Could you rebase your PR? I will take another pass through the code. Thank you for your work here!

- `192.168.*.*`
- `172.16.*.*` through `172.31.*.*`
- The host ends with the machine's default container DNS domain (as defined in `DNSConfig.defaultDomain`, located [here](../Sources/ContainerPersistence/ContainerSystemConfig.swift))
- The host ends with the machine's configured internal DNS domain from `[dns].domain`

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could we add a link to the reference doc here instead?

public static func dnsConfiguration(
from flags: Flags.DNS,
defaults: ContainerDNSConfig,
hostDomainFallback: String? = nil

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What is this for?

Comment on lines +155 to +157
public let nameservers: [String]
public let searchDomains: [String]
public let options: [String]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think about making these optionals instead of empty arrays?


public let cpus: Int
public let memory: MemorySize
public let dns: ContainerDNSConfig

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think about making this an optional as well?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Request]: system property for default --dns.

4 participants

@0xMH@katiewasnothere@am-saksham@jglogan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add TOML configuration for default DNS nameservers, search, options - #1614

Open
0xMH wants to merge 3 commits into
apple:mainfrom
0xMH:fix/1449-dns-defaults
Open

Add TOML configuration for default DNS nameservers, search, options#1614
0xMH wants to merge 3 commits into
apple:mainfrom
0xMH:fix/1449-dns-defaults

Conversation

@0xMH

@0xMH0xMH commented May 28, 2026

Copy link
Copy Markdown
Contributor

Type of Change

  • New feature

Motivation and Context

Closes#1449. Adds default values for --dns, --dns-search, --dns-option, and --dns-domain to the [dns] section of ~/.config/container/config.toml, so users hitting macOS mDNSResponder conflicts can set the workaround once instead of repeating it on every invocation. Depends on the merged TOML configuration introduced by #1425.

Defaults are read by container run, container build, and container builder start via a shared Utility.dnsConfiguration(from:defaults:) helper. CLI flags take precedence; --no-dns still disables DNS. Two pre-existing bugs in the build path were fixed to make the feature work end-to-end: BuildCommand was forwarding only dnsNameservers to the builder (now forwards all four DNS fields), and BuilderStart's dnsChanged check only compared the first non-empty field (now compares all four).

Testing

  • Tested locally
  • Added/updated tests
  • Added/updated docs

}

final public class DNSConfig: Codable, Sendable {
public static let defaultNameservers: [String] = []

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Today there is a subtle difference between what the default DNS settings are for container aka the apiserver itself, which would determine the hostname resolution (aka the A record) for a given container on the host, and the DNS settings for setting up the resolv.conf in a container. I think we should maintain this distinction. There could be scenarios where a user does not want the default DNS domain on the host to necessarily match the default DNS domain that the container application uses in the container itself.

I think we should add a new field on the ContainerConfig type that has the default DNS settings for running a container.

Essentially we'd end up with something like this in the TOML:

[dns] <-------- default DNS settings for the APIServer
domain = "test"
[container.dns] <----------- default DNS settings for containers server = "8.8.8.8"
domain = "foo"
search = ["foo", "test"]
options = ["haha"]

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, good insight. I removed that extra builder startup call.

@0xMH
0xMHforce-pushed the fix/1449-dns-defaults branch 2 times, most recently from 6af7693 to b010238CompareMay 31, 2026 22:56
@0xMH
0xMH requested a review from katiewasnothereJune 1, 2026 18:45
@github-actions

Copy link
Copy Markdown

Code Coverage

TierLine Coverage
Unit34.55%
Integration19.69%
Combined53.62%

@0xMH
0xMHforce-pushed the fix/1449-dns-defaults branch from b010238 to 3eb0a7eCompareJune 2, 2026 17:26
@0xMH
0xMHforce-pushed the fix/1449-dns-defaults branch from 3eb0a7e to 46bd18bCompareJune 3, 2026 23:29
@0xMH

0xMH commented Jun 3, 2026

Copy link
Copy Markdown
ContributorAuthor

Thanks for the review, @katiewasnothere. Happy to iterate further if anything else needs addressing.

@katiewasnotherekatiewasnothere added this to the 2026-06 milestone Jun 3, 2026
@katiewasnothere

Copy link
Copy Markdown
Contributor

Hi @0xMH thank you for all the work you've done on this change! We are planning to make a new release of the container package some time in the next week and we want to hold off on merging this change until then.

@am-saksham

Copy link
Copy Markdown

Hi @0xMH and @katiewasnothere! First, thanks for the great work figuring out the core logic for this.

I noticed this PR has been stalled since the June release and has picked up some merge conflicts. I also saw that a couple of newer PRs for #1449 were opened recently, but they seem to have missed the [dns] vs [container.dns] architectural requirement that Katie pointed out above.

@0xMH, if you are currently swamped with other things, would you mind if I pull your branch, resolve the conflicts against main, and open a fresh PR to get this over the finish line? I will carry over your commits and make sure to include a Co-authored-by tag so you keep full credit for your work.

Let me know if that sounds good!

@0xMH

0xMH commented Jul 5, 2026

Copy link
Copy Markdown
ContributorAuthor

Thanks for the offer! but no need since I'm waiting for the green flag to continue and rebase and prepare for the merge.

@am-saksham

Copy link
Copy Markdown

Awesome, sounds good! Looking forward to seeing it merged. Let me know if you end up needing a hand later on!

@jgloganjglogan removed this from the 2026-06 milestone Jul 7, 2026
@katiewasnothere

Copy link
Copy Markdown
Contributor

@0xMH Really sorry for the delay here, we've been swamped. I'd love to get this in for this sprint (which ends at the end of August). Could you rebase your PR? I will take another pass through the code. Thank you for your work here!

- `192.168.*.*`
- `172.16.*.*` through `172.31.*.*`
- The host ends with the machine's default container DNS domain (as defined in `DNSConfig.defaultDomain`, located [here](../Sources/ContainerPersistence/ContainerSystemConfig.swift))
- The host ends with the machine's configured internal DNS domain from `[dns].domain`

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could we add a link to the reference doc here instead?

public static func dnsConfiguration(
from flags: Flags.DNS,
defaults: ContainerDNSConfig,
hostDomainFallback: String? = nil

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What is this for?

Comment on lines +155 to +157
public let nameservers: [String]
public let searchDomains: [String]
public let options: [String]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think about making these optionals instead of empty arrays?


public let cpus: Int
public let memory: MemorySize
public let dns: ContainerDNSConfig

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think about making this an optional as well?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Request]: system property for default --dns.

4 participants

@0xMH@katiewasnothere@am-saksham@jglogan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Add TOML configuration for default DNS nameservers, search, options - #1614

Open
0xMH wants to merge 3 commits into
apple:mainfrom
0xMH:fix/1449-dns-defaults
Open

Add TOML configuration for default DNS nameservers, search, options#1614
0xMH wants to merge 3 commits into
apple:mainfrom
0xMH:fix/1449-dns-defaults

Conversation

@0xMH

@0xMH0xMH commented May 28, 2026

Copy link
Copy Markdown
Contributor

Type of Change

  • New feature

Motivation and Context

Closes#1449. Adds default values for --dns, --dns-search, --dns-option, and --dns-domain to the [dns] section of ~/.config/container/config.toml, so users hitting macOS mDNSResponder conflicts can set the workaround once instead of repeating it on every invocation. Depends on the merged TOML configuration introduced by #1425.

Defaults are read by container run, container build, and container builder start via a shared Utility.dnsConfiguration(from:defaults:) helper. CLI flags take precedence; --no-dns still disables DNS. Two pre-existing bugs in the build path were fixed to make the feature work end-to-end: BuildCommand was forwarding only dnsNameservers to the builder (now forwards all four DNS fields), and BuilderStart's dnsChanged check only compared the first non-empty field (now compares all four).

Testing

  • Tested locally
  • Added/updated tests
  • Added/updated docs

}

final public class DNSConfig: Codable, Sendable {
public static let defaultNameservers: [String] = []

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Today there is a subtle difference between what the default DNS settings are for container aka the apiserver itself, which would determine the hostname resolution (aka the A record) for a given container on the host, and the DNS settings for setting up the resolv.conf in a container. I think we should maintain this distinction. There could be scenarios where a user does not want the default DNS domain on the host to necessarily match the default DNS domain that the container application uses in the container itself.

I think we should add a new field on the ContainerConfig type that has the default DNS settings for running a container.

Essentially we'd end up with something like this in the TOML:

[dns] <-------- default DNS settings for the APIServer
domain = "test"
[container.dns] <----------- default DNS settings for containers server = "8.8.8.8"
domain = "foo"
search = ["foo", "test"]
options = ["haha"]

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, good insight. I removed that extra builder startup call.

@0xMH
0xMHforce-pushed the fix/1449-dns-defaults branch 2 times, most recently from 6af7693 to b010238CompareMay 31, 2026 22:56
@0xMH
0xMH requested a review from katiewasnothereJune 1, 2026 18:45
@github-actions

Copy link
Copy Markdown

Code Coverage

TierLine Coverage
Unit34.55%
Integration19.69%
Combined53.62%

@0xMH
0xMHforce-pushed the fix/1449-dns-defaults branch from b010238 to 3eb0a7eCompareJune 2, 2026 17:26
@0xMH
0xMHforce-pushed the fix/1449-dns-defaults branch from 3eb0a7e to 46bd18bCompareJune 3, 2026 23:29
@0xMH

0xMH commented Jun 3, 2026

Copy link
Copy Markdown
ContributorAuthor

Thanks for the review, @katiewasnothere. Happy to iterate further if anything else needs addressing.

@katiewasnotherekatiewasnothere added this to the 2026-06 milestone Jun 3, 2026
@katiewasnothere

Copy link
Copy Markdown
Contributor

Hi @0xMH thank you for all the work you've done on this change! We are planning to make a new release of the container package some time in the next week and we want to hold off on merging this change until then.

@am-saksham

Copy link
Copy Markdown

Hi @0xMH and @katiewasnothere! First, thanks for the great work figuring out the core logic for this.

I noticed this PR has been stalled since the June release and has picked up some merge conflicts. I also saw that a couple of newer PRs for #1449 were opened recently, but they seem to have missed the [dns] vs [container.dns] architectural requirement that Katie pointed out above.

@0xMH, if you are currently swamped with other things, would you mind if I pull your branch, resolve the conflicts against main, and open a fresh PR to get this over the finish line? I will carry over your commits and make sure to include a Co-authored-by tag so you keep full credit for your work.

Let me know if that sounds good!

@0xMH

0xMH commented Jul 5, 2026

Copy link
Copy Markdown
ContributorAuthor

Thanks for the offer! but no need since I'm waiting for the green flag to continue and rebase and prepare for the merge.

@am-saksham

Copy link
Copy Markdown

Awesome, sounds good! Looking forward to seeing it merged. Let me know if you end up needing a hand later on!

@jgloganjglogan removed this from the 2026-06 milestone Jul 7, 2026
@katiewasnothere

Copy link
Copy Markdown
Contributor

@0xMH Really sorry for the delay here, we've been swamped. I'd love to get this in for this sprint (which ends at the end of August). Could you rebase your PR? I will take another pass through the code. Thank you for your work here!

- `192.168.*.*`
- `172.16.*.*` through `172.31.*.*`
- The host ends with the machine's default container DNS domain (as defined in `DNSConfig.defaultDomain`, located [here](../Sources/ContainerPersistence/ContainerSystemConfig.swift))
- The host ends with the machine's configured internal DNS domain from `[dns].domain`

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could we add a link to the reference doc here instead?

public static func dnsConfiguration(
from flags: Flags.DNS,
defaults: ContainerDNSConfig,
hostDomainFallback: String? = nil

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What is this for?

Comment on lines +155 to +157
public let nameservers: [String]
public let searchDomains: [String]
public let options: [String]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think about making these optionals instead of empty arrays?


public let cpus: Int
public let memory: MemorySize
public let dns: ContainerDNSConfig

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think about making this an optional as well?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Request]: system property for default --dns.

4 participants

@0xMH@katiewasnothere@am-saksham@jglogan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add TOML configuration for default DNS nameservers, search, options - #1614

Open
0xMH wants to merge 3 commits into
apple:mainfrom
0xMH:fix/1449-dns-defaults
Open

Add TOML configuration for default DNS nameservers, search, options#1614
0xMH wants to merge 3 commits into
apple:mainfrom
0xMH:fix/1449-dns-defaults

Conversation

@0xMH

@0xMH0xMH commented May 28, 2026

Copy link
Copy Markdown
Contributor

Type of Change

  • New feature

Motivation and Context

Closes#1449. Adds default values for --dns, --dns-search, --dns-option, and --dns-domain to the [dns] section of ~/.config/container/config.toml, so users hitting macOS mDNSResponder conflicts can set the workaround once instead of repeating it on every invocation. Depends on the merged TOML configuration introduced by #1425.

Defaults are read by container run, container build, and container builder start via a shared Utility.dnsConfiguration(from:defaults:) helper. CLI flags take precedence; --no-dns still disables DNS. Two pre-existing bugs in the build path were fixed to make the feature work end-to-end: BuildCommand was forwarding only dnsNameservers to the builder (now forwards all four DNS fields), and BuilderStart's dnsChanged check only compared the first non-empty field (now compares all four).

Testing

  • Tested locally
  • Added/updated tests
  • Added/updated docs

}

final public class DNSConfig: Codable, Sendable {
public static let defaultNameservers: [String] = []

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Today there is a subtle difference between what the default DNS settings are for container aka the apiserver itself, which would determine the hostname resolution (aka the A record) for a given container on the host, and the DNS settings for setting up the resolv.conf in a container. I think we should maintain this distinction. There could be scenarios where a user does not want the default DNS domain on the host to necessarily match the default DNS domain that the container application uses in the container itself.

I think we should add a new field on the ContainerConfig type that has the default DNS settings for running a container.

Essentially we'd end up with something like this in the TOML:

[dns] <-------- default DNS settings for the APIServer
domain = "test"
[container.dns] <----------- default DNS settings for containers server = "8.8.8.8"
domain = "foo"
search = ["foo", "test"]
options = ["haha"]

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, good insight. I removed that extra builder startup call.

@0xMH
0xMHforce-pushed the fix/1449-dns-defaults branch 2 times, most recently from 6af7693 to b010238CompareMay 31, 2026 22:56
@0xMH
0xMH requested a review from katiewasnothereJune 1, 2026 18:45
@github-actions

Copy link
Copy Markdown

Code Coverage

TierLine Coverage
Unit34.55%
Integration19.69%
Combined53.62%

@0xMH
0xMHforce-pushed the fix/1449-dns-defaults branch from b010238 to 3eb0a7eCompareJune 2, 2026 17:26
@0xMH
0xMHforce-pushed the fix/1449-dns-defaults branch from 3eb0a7e to 46bd18bCompareJune 3, 2026 23:29
@0xMH

0xMH commented Jun 3, 2026

Copy link
Copy Markdown
ContributorAuthor

Thanks for the review, @katiewasnothere. Happy to iterate further if anything else needs addressing.

@katiewasnotherekatiewasnothere added this to the 2026-06 milestone Jun 3, 2026
@katiewasnothere

Copy link
Copy Markdown
Contributor

Hi @0xMH thank you for all the work you've done on this change! We are planning to make a new release of the container package some time in the next week and we want to hold off on merging this change until then.

@am-saksham

Copy link
Copy Markdown

Hi @0xMH and @katiewasnothere! First, thanks for the great work figuring out the core logic for this.

I noticed this PR has been stalled since the June release and has picked up some merge conflicts. I also saw that a couple of newer PRs for #1449 were opened recently, but they seem to have missed the [dns] vs [container.dns] architectural requirement that Katie pointed out above.

@0xMH, if you are currently swamped with other things, would you mind if I pull your branch, resolve the conflicts against main, and open a fresh PR to get this over the finish line? I will carry over your commits and make sure to include a Co-authored-by tag so you keep full credit for your work.

Let me know if that sounds good!

@0xMH

0xMH commented Jul 5, 2026

Copy link
Copy Markdown
ContributorAuthor

Thanks for the offer! but no need since I'm waiting for the green flag to continue and rebase and prepare for the merge.

@am-saksham

Copy link
Copy Markdown

Awesome, sounds good! Looking forward to seeing it merged. Let me know if you end up needing a hand later on!

@jgloganjglogan removed this from the 2026-06 milestone Jul 7, 2026
@katiewasnothere

Copy link
Copy Markdown
Contributor

@0xMH Really sorry for the delay here, we've been swamped. I'd love to get this in for this sprint (which ends at the end of August). Could you rebase your PR? I will take another pass through the code. Thank you for your work here!

- `192.168.*.*`
- `172.16.*.*` through `172.31.*.*`
- The host ends with the machine's default container DNS domain (as defined in `DNSConfig.defaultDomain`, located [here](../Sources/ContainerPersistence/ContainerSystemConfig.swift))
- The host ends with the machine's configured internal DNS domain from `[dns].domain`

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could we add a link to the reference doc here instead?

public static func dnsConfiguration(
from flags: Flags.DNS,
defaults: ContainerDNSConfig,
hostDomainFallback: String? = nil

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What is this for?

Comment on lines +155 to +157
public let nameservers: [String]
public let searchDomains: [String]
public let options: [String]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think about making these optionals instead of empty arrays?


public let cpus: Int
public let memory: MemorySize
public let dns: ContainerDNSConfig

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think about making this an optional as well?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Request]: system property for default --dns.

4 participants

@0xMH@katiewasnothere@am-saksham@jglogan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add TOML configuration for default DNS nameservers, search, options - #1614

Open
0xMH wants to merge 3 commits into
apple:mainfrom
0xMH:fix/1449-dns-defaults
Open

Add TOML configuration for default DNS nameservers, search, options#1614
0xMH wants to merge 3 commits into
apple:mainfrom
0xMH:fix/1449-dns-defaults

Conversation

@0xMH

@0xMH0xMH commented May 28, 2026

Copy link
Copy Markdown
Contributor

Type of Change

  • New feature

Motivation and Context

Closes#1449. Adds default values for --dns, --dns-search, --dns-option, and --dns-domain to the [dns] section of ~/.config/container/config.toml, so users hitting macOS mDNSResponder conflicts can set the workaround once instead of repeating it on every invocation. Depends on the merged TOML configuration introduced by #1425.

Defaults are read by container run, container build, and container builder start via a shared Utility.dnsConfiguration(from:defaults:) helper. CLI flags take precedence; --no-dns still disables DNS. Two pre-existing bugs in the build path were fixed to make the feature work end-to-end: BuildCommand was forwarding only dnsNameservers to the builder (now forwards all four DNS fields), and BuilderStart's dnsChanged check only compared the first non-empty field (now compares all four).

Testing

  • Tested locally
  • Added/updated tests
  • Added/updated docs

}

final public class DNSConfig: Codable, Sendable {
public static let defaultNameservers: [String] = []

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Today there is a subtle difference between what the default DNS settings are for container aka the apiserver itself, which would determine the hostname resolution (aka the A record) for a given container on the host, and the DNS settings for setting up the resolv.conf in a container. I think we should maintain this distinction. There could be scenarios where a user does not want the default DNS domain on the host to necessarily match the default DNS domain that the container application uses in the container itself.

I think we should add a new field on the ContainerConfig type that has the default DNS settings for running a container.

Essentially we'd end up with something like this in the TOML:

[dns] <-------- default DNS settings for the APIServer
domain = "test"
[container.dns] <----------- default DNS settings for containers server = "8.8.8.8"
domain = "foo"
search = ["foo", "test"]
options = ["haha"]

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, good insight. I removed that extra builder startup call.

@0xMH
0xMHforce-pushed the fix/1449-dns-defaults branch 2 times, most recently from 6af7693 to b010238CompareMay 31, 2026 22:56
@0xMH
0xMH requested a review from katiewasnothereJune 1, 2026 18:45
@github-actions

Copy link
Copy Markdown

Code Coverage

TierLine Coverage
Unit34.55%
Integration19.69%
Combined53.62%

@0xMH
0xMHforce-pushed the fix/1449-dns-defaults branch from b010238 to 3eb0a7eCompareJune 2, 2026 17:26
@0xMH
0xMHforce-pushed the fix/1449-dns-defaults branch from 3eb0a7e to 46bd18bCompareJune 3, 2026 23:29
@0xMH

0xMH commented Jun 3, 2026

Copy link
Copy Markdown
ContributorAuthor

Thanks for the review, @katiewasnothere. Happy to iterate further if anything else needs addressing.

@katiewasnotherekatiewasnothere added this to the 2026-06 milestone Jun 3, 2026
@katiewasnothere

Copy link
Copy Markdown
Contributor

Hi @0xMH thank you for all the work you've done on this change! We are planning to make a new release of the container package some time in the next week and we want to hold off on merging this change until then.

@am-saksham

Copy link
Copy Markdown

Hi @0xMH and @katiewasnothere! First, thanks for the great work figuring out the core logic for this.

I noticed this PR has been stalled since the June release and has picked up some merge conflicts. I also saw that a couple of newer PRs for #1449 were opened recently, but they seem to have missed the [dns] vs [container.dns] architectural requirement that Katie pointed out above.

@0xMH, if you are currently swamped with other things, would you mind if I pull your branch, resolve the conflicts against main, and open a fresh PR to get this over the finish line? I will carry over your commits and make sure to include a Co-authored-by tag so you keep full credit for your work.

Let me know if that sounds good!

@0xMH

0xMH commented Jul 5, 2026

Copy link
Copy Markdown
ContributorAuthor

Thanks for the offer! but no need since I'm waiting for the green flag to continue and rebase and prepare for the merge.

@am-saksham

Copy link
Copy Markdown

Awesome, sounds good! Looking forward to seeing it merged. Let me know if you end up needing a hand later on!

@jgloganjglogan removed this from the 2026-06 milestone Jul 7, 2026
@katiewasnothere

Copy link
Copy Markdown
Contributor

@0xMH Really sorry for the delay here, we've been swamped. I'd love to get this in for this sprint (which ends at the end of August). Could you rebase your PR? I will take another pass through the code. Thank you for your work here!

- `192.168.*.*`
- `172.16.*.*` through `172.31.*.*`
- The host ends with the machine's default container DNS domain (as defined in `DNSConfig.defaultDomain`, located [here](../Sources/ContainerPersistence/ContainerSystemConfig.swift))
- The host ends with the machine's configured internal DNS domain from `[dns].domain`

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could we add a link to the reference doc here instead?

public static func dnsConfiguration(
from flags: Flags.DNS,
defaults: ContainerDNSConfig,
hostDomainFallback: String? = nil

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What is this for?

Comment on lines +155 to +157
public let nameservers: [String]
public let searchDomains: [String]
public let options: [String]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think about making these optionals instead of empty arrays?


public let cpus: Int
public let memory: MemorySize
public let dns: ContainerDNSConfig

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think about making this an optional as well?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Request]: system property for default --dns.

4 participants

@0xMH@katiewasnothere@am-saksham@jglogan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Add TOML configuration for default DNS nameservers, search, options - #1614

Open
0xMH wants to merge 3 commits into
apple:mainfrom
0xMH:fix/1449-dns-defaults
Open

Add TOML configuration for default DNS nameservers, search, options#1614
0xMH wants to merge 3 commits into
apple:mainfrom
0xMH:fix/1449-dns-defaults

Conversation

@0xMH

@0xMH0xMH commented May 28, 2026

Copy link
Copy Markdown
Contributor

Type of Change

  • New feature

Motivation and Context

Closes#1449. Adds default values for --dns, --dns-search, --dns-option, and --dns-domain to the [dns] section of ~/.config/container/config.toml, so users hitting macOS mDNSResponder conflicts can set the workaround once instead of repeating it on every invocation. Depends on the merged TOML configuration introduced by #1425.

Defaults are read by container run, container build, and container builder start via a shared Utility.dnsConfiguration(from:defaults:) helper. CLI flags take precedence; --no-dns still disables DNS. Two pre-existing bugs in the build path were fixed to make the feature work end-to-end: BuildCommand was forwarding only dnsNameservers to the builder (now forwards all four DNS fields), and BuilderStart's dnsChanged check only compared the first non-empty field (now compares all four).

Testing

  • Tested locally
  • Added/updated tests
  • Added/updated docs

}

final public class DNSConfig: Codable, Sendable {
public static let defaultNameservers: [String] = []

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Today there is a subtle difference between what the default DNS settings are for container aka the apiserver itself, which would determine the hostname resolution (aka the A record) for a given container on the host, and the DNS settings for setting up the resolv.conf in a container. I think we should maintain this distinction. There could be scenarios where a user does not want the default DNS domain on the host to necessarily match the default DNS domain that the container application uses in the container itself.

I think we should add a new field on the ContainerConfig type that has the default DNS settings for running a container.

Essentially we'd end up with something like this in the TOML:

[dns] <-------- default DNS settings for the APIServer
domain = "test"
[container.dns] <----------- default DNS settings for containers server = "8.8.8.8"
domain = "foo"
search = ["foo", "test"]
options = ["haha"]

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, good insight. I removed that extra builder startup call.

@0xMH
0xMHforce-pushed the fix/1449-dns-defaults branch 2 times, most recently from 6af7693 to b010238CompareMay 31, 2026 22:56
@0xMH
0xMH requested a review from katiewasnothereJune 1, 2026 18:45
@github-actions

Copy link
Copy Markdown

Code Coverage

TierLine Coverage
Unit34.55%
Integration19.69%
Combined53.62%

@0xMH
0xMHforce-pushed the fix/1449-dns-defaults branch from b010238 to 3eb0a7eCompareJune 2, 2026 17:26
@0xMH
0xMHforce-pushed the fix/1449-dns-defaults branch from 3eb0a7e to 46bd18bCompareJune 3, 2026 23:29
@0xMH

0xMH commented Jun 3, 2026

Copy link
Copy Markdown
ContributorAuthor

Thanks for the review, @katiewasnothere. Happy to iterate further if anything else needs addressing.

@katiewasnotherekatiewasnothere added this to the 2026-06 milestone Jun 3, 2026
@katiewasnothere

Copy link
Copy Markdown
Contributor

Hi @0xMH thank you for all the work you've done on this change! We are planning to make a new release of the container package some time in the next week and we want to hold off on merging this change until then.

@am-saksham

Copy link
Copy Markdown

Hi @0xMH and @katiewasnothere! First, thanks for the great work figuring out the core logic for this.

I noticed this PR has been stalled since the June release and has picked up some merge conflicts. I also saw that a couple of newer PRs for #1449 were opened recently, but they seem to have missed the [dns] vs [container.dns] architectural requirement that Katie pointed out above.

@0xMH, if you are currently swamped with other things, would you mind if I pull your branch, resolve the conflicts against main, and open a fresh PR to get this over the finish line? I will carry over your commits and make sure to include a Co-authored-by tag so you keep full credit for your work.

Let me know if that sounds good!

@0xMH

0xMH commented Jul 5, 2026

Copy link
Copy Markdown
ContributorAuthor

Thanks for the offer! but no need since I'm waiting for the green flag to continue and rebase and prepare for the merge.

@am-saksham

Copy link
Copy Markdown

Awesome, sounds good! Looking forward to seeing it merged. Let me know if you end up needing a hand later on!

@jgloganjglogan removed this from the 2026-06 milestone Jul 7, 2026
@katiewasnothere

Copy link
Copy Markdown
Contributor

@0xMH Really sorry for the delay here, we've been swamped. I'd love to get this in for this sprint (which ends at the end of August). Could you rebase your PR? I will take another pass through the code. Thank you for your work here!

- `192.168.*.*`
- `172.16.*.*` through `172.31.*.*`
- The host ends with the machine's default container DNS domain (as defined in `DNSConfig.defaultDomain`, located [here](../Sources/ContainerPersistence/ContainerSystemConfig.swift))
- The host ends with the machine's configured internal DNS domain from `[dns].domain`

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could we add a link to the reference doc here instead?

public static func dnsConfiguration(
from flags: Flags.DNS,
defaults: ContainerDNSConfig,
hostDomainFallback: String? = nil

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What is this for?

Comment on lines +155 to +157
public let nameservers: [String]
public let searchDomains: [String]
public let options: [String]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think about making these optionals instead of empty arrays?


public let cpus: Int
public let memory: MemorySize
public let dns: ContainerDNSConfig

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think about making this an optional as well?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Request]: system property for default --dns.

4 participants

@0xMH@katiewasnothere@am-saksham@jglogan