nix: move the reader-after-policy edges into their own colocation glue
The four readers' ordering after their policy units only applies where the store and that reader share a host, so it is colocation glue and does not belong in the reader modules (two of which are main modules). glue-bao-readers-policy-order.nix now sets the after+wants edges, gated on deploy.bao.enable AND the reader's own gate, so a store host without a reader gains no stub unit.
This commit is contained in:
parent
cde3fec956
commit
0bfe354b6d
7 changed files with 127 additions and 42 deletions
|
|
@ -57,6 +57,43 @@ let
|
|||
deploy.swarm-otel.enable = true;
|
||||
};
|
||||
|
||||
# The store with none of the four readers beside it. Grafana, the collector and
|
||||
# the homeserver are simply off; the queue reader renders on any host holding
|
||||
# its leaf, which ./glue-bao-tls.nix mints here, so that leaf is taken away.
|
||||
baoGrantNoReaders = hive {
|
||||
deploy.bao.enable = true;
|
||||
deploy.bao.bootstrapTokenFile = "/run/secrets/bao-bootstrap.token";
|
||||
deploy.bao.queueAgentClientCertFile = lib.mkForce null;
|
||||
deploy.bao.queueAgentClientKeyFile = lib.mkForce null;
|
||||
};
|
||||
|
||||
# All four readers against a store they do not run, each with a leaf placed
|
||||
# by hand. The deployment in which there is no local policy unit to wait for.
|
||||
baoRemoteReaders = hive {
|
||||
deploy.matrix.enable = true;
|
||||
deploy.grafana.enable = true;
|
||||
deploy.swarm-otel.enable = true;
|
||||
deploy.bao.clientCertFile = "/etc/pki/bao-client.pem";
|
||||
deploy.bao.clientKeyFile = "/etc/pki/bao-client-key.pem";
|
||||
deploy.bao.matrixTokenClientCertFile = "/etc/pki/bao-matrix-token.pem";
|
||||
deploy.bao.matrixTokenClientKeyFile = "/etc/pki/bao-matrix-token-key.pem";
|
||||
deploy.bao.queueAgentClientCertFile = "/etc/pki/bao-queue-agent.pem";
|
||||
deploy.bao.queueAgentClientKeyFile = "/etc/pki/bao-queue-agent-key.pem";
|
||||
deploy.bao.grafanaOidcClientCertFile = "/etc/pki/bao-grafana-oidc.pem";
|
||||
deploy.bao.grafanaOidcClientKeyFile = "/etc/pki/bao-grafana-oidc-key.pem";
|
||||
deploy.bao.otelOidcClientCertFile = "/etc/pki/bao-otel-oidc.pem";
|
||||
deploy.bao.otelOidcClientKeyFile = "/etc/pki/bao-otel-oidc-key.pem";
|
||||
};
|
||||
|
||||
# The four readers ./glue-bao-readers-policy-order.nix orders after their
|
||||
# policy units.
|
||||
policyReaders = [
|
||||
"swarm-bao-matrix-token"
|
||||
"swarm-bao-queue-agent"
|
||||
"swarm-bao-grafana-oidc"
|
||||
"swarm-bao-otel-oidc"
|
||||
];
|
||||
|
||||
cases = [
|
||||
{
|
||||
# Reads the rendered unit on the HOST, which is where the write happens:
|
||||
|
|
@ -455,12 +492,31 @@ let
|
|||
&& lib.elem policy s.${reader}.wants
|
||||
&& !(lib.elem policy s.${reader}.requires);
|
||||
in
|
||||
lib.all waitsFor [
|
||||
"swarm-bao-matrix-token"
|
||||
"swarm-bao-queue-agent"
|
||||
"swarm-bao-grafana-oidc"
|
||||
"swarm-bao-otel-oidc"
|
||||
];
|
||||
lib.all waitsFor policyReaders;
|
||||
}
|
||||
{
|
||||
# The ordering is set apart from each reader's own definition, so it can
|
||||
# define a reader by itself: `after` on a unit nothing else declares is a
|
||||
# unit with no ExecStart. On the store's host without the readers, none
|
||||
# of the four may exist.
|
||||
name = "a store host without the readers gains no reader unit from their ordering";
|
||||
ok = lib.all (reader: !(baoGrantNoReaders.systemd.services ? ${reader})) policyReaders;
|
||||
}
|
||||
{
|
||||
# Where the store is remote there is no policy unit here to wait for, so
|
||||
# the readers render as they did before the ordering existed.
|
||||
name = "a reader whose store is remote is not ordered after a policy unit";
|
||||
ok =
|
||||
let
|
||||
s = baoRemoteReaders.systemd.services;
|
||||
unordered =
|
||||
reader:
|
||||
let
|
||||
policy = "${reader}-policy.service";
|
||||
in
|
||||
s ? ${reader} && !(lib.elem policy s.${reader}.after) && !(lib.elem policy s.${reader}.wants);
|
||||
in
|
||||
lib.all unordered policyReaders;
|
||||
}
|
||||
{
|
||||
# A store host that has not placed a bootstrap token can write no grant at
|
||||
|
|
|
|||
Loading…
Reference in a new issue