Hetzner OS publishes 4 systemd-resolved upstreams and Kubernetes limits
pod resolv.conf to 3 nameservers, so kubelet drops the 4th and fires a
DNSConfigForming Warning event on every hostNetwork or dnsPolicy=Default
pod restart. Silence the noise by pinning the pods to 3 explicit servers
(same 3 kubelet was already picking).
- apps/observability/patches/node-exporter-dns-config.yaml — strategic-
merge patch adding dnsPolicy=None + dnsConfig to the
kube-prometheus-stack node-exporter DaemonSet (Helm-managed, applied
by hand)
- apps/observability/patches/coredns-dns-config.yaml — companion patch
for the k3s built-in CoreDNS Deployment. kubectl patch alone is not
durable because the k3s addon controller reverts dnsPolicy; kept as a
quick manual re-apply hook
- infrastructure/k3s-manifests/coredns.yaml — the authoritative modified
k3s addon manifest that must live at
/var/lib/rancher/k3s/server/manifests/coredns.yaml on all 3 CP nodes
- infrastructure/k3s-manifests/README-DEV-527.md — apply procedure,
verification steps, and upgrade caveat
Applied and verified on the live cluster:
- node-exporter DaemonSet rolled with dnsPolicy=None; no
DNSConfigForming events on current pods
- coredns Deployment reconciled after pushing the modified manifest to
all 3 CPs; new pod runs with dnsPolicy=None and 3-nameserver dnsConfig
- internal + external DNS resolution still works
Co-Authored-By: Paperclip <noreply@paperclip.ing>