feat(3088): move the gateway's nginx + dnsmasq onto the host
The gateway's nginx + dnsmasq no longer run in their own nspawn container. `nix/host-modules/hive-gateway/default.nix` loses the `containers.hive-gateway` wrapper and everything that existed only to punch holes in it: `privateNetwork = false`, `CAP_NET_ADMIN`, five bind mounts, its own `stateVersion`, `networking.firewall.enable = false`, `networking.resolvconf.enable = false`, and the `hive-gateway-resolv` path+service pair. 465 -> 303 lines. The container never bought isolation here. It shared the host netns by necessity — nginx binds the host's :80/:443, dnsmasq answers on the bridge — so each of those settings was undoing a boundary the gateway could not afford in the first place. Four things made it more than a deletion, none of them visible in the nix diff: - The self-signed cert service also imports the hive CA leaf, so removing it with the container would have left nginx naming a missing cert file, which it refuses to load at all. - The nginx reload is a hive-priv verb. It still needs root, but no longer for the reason its doc gave, and `--machine=` was both transport and scope — so the unit name is now hard-coded in the helper as the containment. - The lifecycle verb named a container that stops existing. - `journalctl -M hive-gateway` had no machine to enter. Per the operator's ruling, the operator verb keeps working and agents lose it. `InfraContainer` answered three questions that used to share an answer; it now splits into `name()` (identity), `target()` (Container vs HostUnit), `service_unit()` (the systemd unit), and `agent_restartable()`, which the MCP restart path checks before the capability so the refusal cannot read as "ask for infra_admin". `SIBLING_CONTAINERS` drops the gateway — it gates the requests that name a container as a string — while `FromStr` still accepts it, because that answers what a name is, not who may act on it. The dashboard's gateway journal reads host journald filtered to `nginx.service`. Prose was corrected where it only named a location, and re-argued where the container was doing security work: a `0666` per-agent socket was safe because only the gateway container had the directory bind-mounted. There is no mount now, so the directory permissions are the whole of the access control — the constraint holds, its mechanism doesn't. Gate: nix fmt / clippy --all-targets -D warnings / cargo test all clean (710 tests); hivectl-cli.md regenerated from the clap tree. The nix eval was run in both TLS shapes at this commit: every delta in the rendered virtualHosts is one of the three intended path moves, dnsmasq settings are byte-identical, and the absence probe flips true -> false with bindMounts emptied.
This commit is contained in:
parent
cae2cf8df6
commit
07852cabc1
34 changed files with 704 additions and 618 deletions
|
|
@ -1,9 +1,13 @@
|
|||
//! Dashboard endpoint for operator-driven infra-container lifecycle
|
||||
//! (start / stop / restart on `hive-ci`, `hive-forge`, `hive-gateway`,
|
||||
//! `hive-matrix`). Parallels the `infra_admin`-gated agent path in
|
||||
//! Dashboard endpoint for operator-driven infra lifecycle (start / stop /
|
||||
//! restart on `hive-ci`, `hive-forge`, `hive-gateway`, `hive-matrix`).
|
||||
//! Parallels the `infra_admin`-gated agent path in
|
||||
//! `socket_server/lifecycle_handlers.rs::handle_restart_infra`, but this one
|
||||
//! is reached from the dashboard — already fully operator-authenticated —
|
||||
//! so no capability check is needed here, just the same audit trail.
|
||||
//!
|
||||
//! The two surfaces no longer cover the same set: the gateway is the
|
||||
//! operator's to restart and not an agent's, since nginx on the host fronts
|
||||
//! every hive service. This endpoint keeps all four.
|
||||
|
||||
use axum::{
|
||||
extract::{Path as AxumPath, State},
|
||||
|
|
@ -27,7 +31,7 @@ use super::{AppState, error_response};
|
|||
post,
|
||||
path = "/api/infra-container/{name}/{action}",
|
||||
params(
|
||||
("name" = String, Path, description = "infra container name (hive-ci/hive-forge/hive-gateway/hive-matrix)"),
|
||||
("name" = String, Path, description = "infra service name (hive-ci/hive-forge/hive-gateway/hive-matrix)"),
|
||||
("action" = String, Path, description = "start | stop | restart"),
|
||||
),
|
||||
responses(
|
||||
|
|
@ -53,8 +57,8 @@ pub(super) async fn post_infra_container(
|
|||
));
|
||||
}
|
||||
};
|
||||
let unit = container.unit_name();
|
||||
tracing::info!(%unit, %action, "dashboard: infra container action");
|
||||
let target = container.name();
|
||||
tracing::info!(%target, %action, "dashboard: infra container action");
|
||||
let result = crate::priv_client::control_infra_container(container, infra_action).await;
|
||||
let outcome = if result.is_ok() {
|
||||
crate::audit_log::AuditOutcome::Ok
|
||||
|
|
@ -66,12 +70,12 @@ pub(super) async fn post_infra_container(
|
|||
state
|
||||
.coord
|
||||
.audit_log
|
||||
.record("operator", action_label, unit, outcome, detail.as_deref())
|
||||
.record("operator", action_label, target, outcome, detail.as_deref())
|
||||
{
|
||||
state.coord.emit_audit_entry(entry);
|
||||
}
|
||||
match result {
|
||||
Ok(()) => (StatusCode::OK, "ok").into_response(),
|
||||
Err(e) => error_response(&format!("{unit}: {e:#}")),
|
||||
Err(e) => error_response(&format!("{target}: {e:#}")),
|
||||
}
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in a new issue