nix: share the service-container settings through one in-container module
The ten hand-rolled `containers.<name>` blocks each repeat the same
in-container lines: `system.stateVersion`, a firewall turned off because
the container shares the host netns, and resolvconf forced off because
something in the container writes /etc/resolv.conf itself.
`nix/host-modules/swarm-container.nix` now owns those lines. It is
imported inside the container's own config and exposes
`services.hyperhive.swarmContainer.{privateNetwork,writesOwnResolvConf}`
for the host module to set. `stateVersion` is a `mkDefault`, so the two
containers on another value can keep theirs. `--link-journal=host` stays
per module, and so do the host-side attrs (autoStart, ephemeral,
privateNetwork, bindMounts).
swarm-victoriametrics is converted as the first user. Its container
toplevel drvPath is unchanged. A module-eval case now forces that
container's config, which nothing in the suite read before.
Refs #3773
This commit is contained in:
parent
544a8dd228
commit
024067f3f8
3 changed files with 74 additions and 14 deletions
|
|
@ -185,6 +185,21 @@ let
|
|||
&& !(swarmServicesOnly.systemd.sockets ? hive-priv)
|
||||
&& !(s ? swarm-bao-queue-agent);
|
||||
}
|
||||
{
|
||||
# Both values come from ../host-modules/swarm-container.nix. Read
|
||||
# through the metrics store: nothing else in this suite evaluates that
|
||||
# container's config.
|
||||
name = "a service container on the host netns runs no firewall or resolvconf of its own";
|
||||
ok =
|
||||
let
|
||||
c = swarmServicesOnly.containers.swarm-victoriametrics.config;
|
||||
in
|
||||
!c.networking.firewall.enable && !c.networking.resolvconf.enable;
|
||||
}
|
||||
{
|
||||
name = "a service container that sets no stateVersion of its own is on 26.05";
|
||||
ok = swarmServicesOnly.containers.swarm-victoriametrics.config.system.stateVersion == "26.05";
|
||||
}
|
||||
{
|
||||
# An operator's explicit `false` beats every `mkDefault` assertion,
|
||||
# which is what keeps "asserted by whoever needs it" from being a
|
||||
|
|
|
|||
Loading…
Reference in a new issue