nix: move the remaining service containers onto the swarm-container module
hive-ci, hive-forge, hive-matrix, swarm-authelia, swarm-bao, swarm-grafana, swarm-nats, swarm-otel and swarm-victorialogs now import ./swarm-container.nix and drop their own copies of the stateVersion, firewall and resolvconf lines. Each binds privateNetwork once in its top-level let and passes it to both the host attr and the in-container option, as swarm-victoriametrics already does. hive-forge (25.11) and swarm-otel (the host's value) keep their own stateVersion over the module's mkDefault. hive-ci sets privateNetwork = true and writesOwnResolvConf = false, which leaves its firewall and resolvconf on, as before. hive-matrix keeps its useHostResolvConf override and static resolv.conf; its resolvconf mkForce now comes from the module default. Every container's system.build.toplevel drvPath and host-side attrs evaluate identical to the parent commit. module-eval-swarm-services-switch gains a fixture with all ten service containers and checks that each one's in-container privateNetwork equals its host-side value, that the nine on the host netns run no firewall or resolvconf, that hive-ci keeps both, and that hive-forge keeps its pinned stateVersion. Refs #3773
This commit is contained in:
parent
53d9ebdede
commit
10d579ecaf
10 changed files with 133 additions and 135 deletions
|
|
@ -49,6 +49,12 @@ let
|
|||
consumers = [ "gitea-runner-hive" ];
|
||||
};
|
||||
|
||||
# Private network namespace, attached to the hive bridge so the
|
||||
# runner reaches the forge via the gateway — and cannot reach
|
||||
# host-loopback (127.0.0.1:7000 dashboard, raw forge port, etc.).
|
||||
# Requires `deploy.forgejo.behindGateway = true` (asserted in the
|
||||
# config block below). See docs/networking/network.md.
|
||||
privateNetwork = true;
|
||||
in
|
||||
{
|
||||
# Forgejo Actions runner in a `hive-ci` nixos-container.
|
||||
|
|
@ -235,12 +241,7 @@ in
|
|||
# Journal files on the host, not inside the container: nixpkgs hardcodes
|
||||
# --link-journal=try-guest, and EXTRA_NSPAWN_FLAGS expands after it.
|
||||
extraFlags = [ "--link-journal=host" ];
|
||||
# Private network namespace, attached to the hive bridge so the
|
||||
# runner reaches the forge via the gateway — and cannot reach
|
||||
# host-loopback (127.0.0.1:7000 dashboard, raw forge port, etc.).
|
||||
# Requires `deploy.forgejo.behindGateway = true` (asserted in the
|
||||
# options block above). See docs/networking/network.md.
|
||||
privateNetwork = true;
|
||||
inherit privateNetwork;
|
||||
hostBridge = networkCfg.bridgeName;
|
||||
|
||||
bindMounts = {
|
||||
|
|
@ -277,9 +278,17 @@ in
|
|||
# Assembles system CAs + the hive CA into one bundle and sets
|
||||
# `SSL_CERT_FILE` on the runner unit. See `caBundleModule` above for
|
||||
# why the Node variable beside it is not enough.
|
||||
imports = [ caBundleModule ];
|
||||
imports = [
|
||||
../container-modules/swarm-container.nix
|
||||
caBundleModule
|
||||
];
|
||||
|
||||
system.stateVersion = "26.05";
|
||||
# Its own netns, so it keeps its own firewall; resolvconf stays on
|
||||
# and serves `networking.nameservers` below.
|
||||
services.hyperhive.swarmContainer = {
|
||||
inherit privateNetwork;
|
||||
writesOwnResolvConf = false;
|
||||
};
|
||||
|
||||
# Point the forge domain at the bridge IP so the runner can
|
||||
# reach the forge through the gateway — both for registration /
|
||||
|
|
|
|||
Loading…
Reference in a new issue