UpdatesExplore the release notes

Learn · Lesson 5 of 7 · 5 min

Names and DNS

Reach a machine by name, give a service a familiar address, or keep using your existing internal DNS.

01 / NAME YOUR MACHINES

Your device name is its DNS name.

Enable private DNS. A device named build-01 automatically gets the DNS name build-01.acme.internal. You don’t need to create a separate DNS record for each device.

Device name → DNS nameExample
build-01automatically available asbuild-01.acme.internalresolves to100.64.0.12

Use your own organization domain. Baseguard resolves the device name to its private address.

ssh build-01.acme.internal

With your organization domain configured as a search domain, you can use the short name too: ssh build-01.

02 / NAME A SERVICE

Make the dashboard easy to find.

In DNS → Records, add an A record pointing your service name at the node’s private IPv4 address.

Custom recordExample
Domain
grafana.corp.internal
Type
A
Target
100.64.0.12
TTL
300 seconds

A name helps devices find the service. Network rules still decide whether they can connect.

03 / KEEP YOUR INTERNAL DNS

Send internal queries to your resolver.

Add your nameserver with a Match Domain, such as corp.internal.

Split DNSExample
corp.internal
Matching queries
Your nameserver

If that resolver is unavailable, these queries fail. They do not fall back to a public resolver.

A few useful details

Resolution order. Node names → custom records → matching split DNS → default nameservers → system resolver. The most specific split DNS suffix wins.

Local resolver. Each daemon runs its own resolver at the first address of the overlay range, 100.64.0.1 by default. Only the local node can query it.

Records. A and AAAA records are supported. TTL is 60–86400 seconds, with 300 as the default. Scope records to tags to choose which nodes see them.

Wildcards. A single leading wildcard such as *.corp.internal matches one label below that domain.

Upstream nameservers. Plain DNS on port 53, up to 8 addresses per nameserver. DoT and DoH upstream are not supported. Default nameservers are queried in parallel; the first answer wins.

Your services have familiar names.

Next, find the record of the changes you’ve made.