nix: move the reader-after-policy edges into their own colocation glue

The four readers' ordering after their policy units only applies where
the store and that reader share a host, so it is colocation glue and
does not belong in the reader modules (two of which are main modules).
glue-bao-readers-policy-order.nix now sets the after+wants edges, gated
on deploy.bao.enable AND the reader's own gate, so a store host without
a reader gains no stub unit.
This commit is contained in:
atlas 2026-09-24 14:04:49 +02:00 • committed by mara
commit 0bfe354b6d
7 changed files with 127 additions and 42 deletions

View file

@ -161,19 +161,11 @@ in
# `Requires=` on an absent unit fails the job outright, so the ordering is
# conditional even though the read is not: off-host there is nothing local
# to wait for, and the timeout below is what bounds the attempt instead.
#
# The policy unit writes the role this reader logs in with. Ordering
# only: it skips once the bootstrap token is gone, and a skipped unit
# counts as done.
after = lib.optionals baoDeploy.enable [
"swarm-bao-pki.service"
"container@${baoCfg.machine}.service"
"swarm-bao-queue-agent-policy.service"
];
wants = lib.optionals baoDeploy.enable [
"container@${baoCfg.machine}.service"
"swarm-bao-queue-agent-policy.service"
];
wants = lib.optionals baoDeploy.enable [ "container@${baoCfg.machine}.service" ];
requires = lib.optionals baoDeploy.enable [ "swarm-bao-pki.service" ];
# Ordered before hive-c0re, so no agent container renders ahead of an
# attempt at its credential. `Wants=`, not `Requires=`: a store this