/etc/resolv.conf 를 열었더니 네임서버가 한 줄뿐이고 주소가 낯설다.
nameserver 127.0.0.53
options edns0 trust-ad
search example.com
파일 자체가 심볼릭 링크인 경우도 많다.
ls -l /etc/resolv.conf
/etc/resolv.conf -> ../run/systemd/resolve/stub-resolv.conf
127.0.0.53 은 systemd-resolved 가 로컬에서 듣고 있는 스텁 리졸버다. 애플리케이션은 이 주소로 질의하고, systemd-resolved 가 진짜 상위 DNS 로 대신 물어본다.
애플리케이션 -> 127.0.0.53 (systemd-resolved) -> 실제 DNS 서버
systemd-resolved 는 두 가지 형태의 resolv.conf 를 만든다. 어느 쪽을 링크하느냐에 따라 동작이 달라진다.
| 파일 | 내용 | 효과 |
|---|---|---|
/run/systemd/resolve/stub-resolv.conf |
nameserver 127.0.0.53 |
모든 질의가 resolved 를 거친다. 캐시, DNSSEC, 링크별 DNS 가 동작한다 |
/run/systemd/resolve/resolv.conf |
실제 상위 DNS 주소 | 애플리케이션이 상위 DNS 로 직접 간다. resolved 의 기능을 쓰지 않는다 |
기본은 스텁 쪽이다.
/etc/resolv.conf 만 봐서는 어디로 나가는지 알 수 없다. resolved 에게 직접 묻는다.
resolvectl status
인터페이스별로 DNS Servers, DNS Domain 이 나온다. 질의 경로를 따라가 보려면 다음을 쓴다.
resolvectl query example.com
캐시를 비운다.
sudo resolvectl flush-caches
/etc/resolv.conf 가 링크인 상태에서 그 파일을 편집하면 링크 대상이 바뀌거나 다음 재기동에 덮인다. 고정하려면 링크를 끊고 관리 주체를 꺼야 한다.
sudo systemctl disable --now systemd-resolved
sudo rm -f /etc/resolv.conf
sudo tee /etc/resolv.conf > /dev/null <<'RESOLV'
search example.com
nameserver 10.0.0.53
nameserver 10.0.0.54
options timeout:2 attempts:2
RESOLV
NetworkManager 가 함께 관리하는 환경이라면 그쪽도 꺼야 한다. 설정 방법은 NetworkManager 의 resolv.conf 제어 에 정리돼 있다.
resolved 를 끄기 전에 그 기능에 기대는 것이 없는지 확인한다. 컨테이너 런타임이나 VPN 클라이언트가 링크별 DNS 를 쓰고 있으면 함께 깨진다.
관리 주체를 끄지 않고 값만 바꾸는 편이 안전하다.
sudo vi /etc/systemd/resolved.conf
[Resolve]
DNS=10.0.0.53 10.0.0.54
FallbackDNS=
Domains=example.com
DNSStubListener=yes
sudo systemctl restart systemd-resolved
resolvectl status
FallbackDNS= 를 비워 두는 것이 중요하다. 비워 두지 않으면 사내 DNS 가 응답하지 않을 때 공용 DNS 로 새어 나간다. 폐쇄망이나 내부 도메인만 쓰는 환경에서는 반드시 비운다.
/etc/hosts 항목이 잘못돼 있으면 resolved 가 다음과 같이 남긴다.
/etc/hosts:12: address "i10.194.49.34" is invalid, ignoring
주소 자리에 주소가 아닌 값이 들어간 경우다. 줄 번호를 그대로 찾아 고친다. 오타 하나로 그 줄 전체가 무시되므로 해당 호스트 이름만 해석되지 않는 증상이 된다.
sed -n '12p' /etc/hosts