[PR #4579] [MERGED] [client] Explicitly disable DNSOverTLS for systemd-resolved #23657

Closed
opened 2026-08-05 06:07:34 -04:00 by saavagebueno · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/netbirdio/netbird/pull/4579
Author: @kleschenko
Created: 10/2/2025
Status: Merged
Merged: 10/10/2025
Merged by: @lixmal

Base: mainHead: disable-dnsovertls


📝 Commits (1)

  • 6a899e4 [client] Explicitly disable DNSOverTLS for systemd-resolved

📊 Changes

1 file changed (+6 additions, -0 deletions)

View changed files

📝 client/internal/dns/systemd_linux.go (+6 -0)

📄 Description

Describe your changes

This change explicitly disables DNSOverTLS for the Netbird wg interface on systems using systemd-resolved. Currently, if the system has DNS over TLS enabled globally then netbird interface will inherit it and DNS resolution ends up in a broken state. Disabling dnsovertls setting explicitly for interface fixes this issue.

Updates https://github.com/netbirdio/netbird/issues/1483

Stack

Checklist

  • Is it a bug fix
  • Is a typo/documentation fix
  • Is a feature enhancement
  • It is a refactor
  • Created tests that fail without the change (if possible)

By submitting this pull request, you confirm that you have read and agree to the terms of the Contributor License Agreement.

Documentation

Select exactly one:

  • I added/updated documentation for this change
  • Documentation is not needed for this change (explain why)

Docs PR URL (required if "docs added" is checked)

Paste the PR link from https://github.com/netbirdio/docs here:

https://github.com/netbirdio/docs/pull/__


🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/netbirdio/netbird/pull/4579 **Author:** [@kleschenko](https://github.com/kleschenko) **Created:** 10/2/2025 **Status:** ✅ Merged **Merged:** 10/10/2025 **Merged by:** [@lixmal](https://github.com/lixmal) **Base:** `main` ← **Head:** `disable-dnsovertls` --- ### 📝 Commits (1) - [`6a899e4`](https://github.com/netbirdio/netbird/commit/6a899e4eee2af2cd458bb22110f28b0999fff522) [client] Explicitly disable DNSOverTLS for systemd-resolved ### 📊 Changes **1 file changed** (+6 additions, -0 deletions) <details> <summary>View changed files</summary> 📝 `client/internal/dns/systemd_linux.go` (+6 -0) </details> ### 📄 Description ## Describe your changes This change explicitly disables DNSOverTLS for the Netbird wg interface on systems using systemd-resolved. Currently, if the system has DNS over TLS enabled globally then netbird interface will inherit it and DNS resolution ends up in a broken state. [Disabling `dnsovertls` setting explicitly](https://github.com/netbirdio/netbird/issues/1483#issuecomment-2828820511) for interface fixes this issue. ## Issue ticket number and link Updates https://github.com/netbirdio/netbird/issues/1483 ## Stack <!-- branch-stack --> ### Checklist - [x] Is it a bug fix - [ ] Is a typo/documentation fix - [ ] Is a feature enhancement - [ ] It is a refactor - [ ] Created tests that fail without the change (if possible) > By submitting this pull request, you confirm that you have read and agree to the terms of the [Contributor License Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md). ## Documentation Select exactly one: - [ ] I added/updated documentation for this change - [x] Documentation is **not needed** for this change (explain why) ### Docs PR URL (required if "docs added" is checked) Paste the PR link from https://github.com/netbirdio/docs here: https://github.com/netbirdio/docs/pull/__ --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
saavagebueno added the pull-request label 2026-08-05 06:07:34 -04:00
Sign in to join this conversation.
No Label pull-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#23657