7 DNS ndots shenanigans
Steffo edited this page 2026-08-25 08:28:17 +00:00

DNS ndots shenanigans

Oracle Cloud sets a DNS domain by default, tartarus.underworld.oraclevcn.com.

Kubernetes uses the ndots:5 resolv.conf option 1, and appends the host's DNS domain to the pod's resolv.conf.

The service at postgresql-rw.steffo-www.svc.cluster.local has 4 dots in it and no final dot, so it is prefixed to all DNS domains in reverse order.

This means that postgresql-rw.steffo-www.svc.cluster.local.tartarus.underworld.oraclevcn.com is looked up and resolution fails because tartarus.underworld.oraclevcn.com doesn't exist outside Oracle Cloud.

The attempted fix number 3 is:

  1. rename the /etc/resolv.conf stub left by systemd-resolved to /etc/resolv.conf.stub.
  2. create a new static /etc/resolv.conf without the DNS domain:
    nameserver 127.0.0.53
    options edns0 trust-ad