nix: move the remaining service containers onto the swarm-container module
hive-ci, hive-forge, hive-matrix, swarm-authelia, swarm-bao, swarm-grafana, swarm-nats, swarm-otel and swarm-victorialogs now import ./swarm-container.nix and drop their own copies of the stateVersion, firewall and resolvconf lines. Each binds privateNetwork once in its top-level let and passes it to both the host attr and the in-container option, as swarm-victoriametrics already does. hive-forge (25.11) and swarm-otel (the host's value) keep their own stateVersion over the module's mkDefault. hive-ci sets privateNetwork = true and writesOwnResolvConf = false, which leaves its firewall and resolvconf on, as before. hive-matrix keeps its useHostResolvConf override and static resolv.conf; its resolvconf mkForce now comes from the module default. Every container's system.build.toplevel drvPath and host-side attrs evaluate identical to the parent commit. module-eval-swarm-services-switch gains a fixture with all ten service containers and checks that each one's in-container privateNetwork equals its host-side value, that the nine on the host netns run no firewall or resolvconf, that hive-ci keeps both, and that hive-forge keeps its pinned stateVersion. Refs #3773
This commit is contained in:
parent
53d9ebdede
commit
10d579ecaf
10 changed files with 133 additions and 135 deletions
|
|
@ -1208,6 +1208,12 @@ let
|
|||
api_addr = "https://${cfg.domain}:${toString cfg.port}";
|
||||
cluster_addr = "https://${cfg.domain}:${toString (cfg.port + 1)}";
|
||||
};
|
||||
|
||||
# Shared host netns, like every sibling swarm container. Unlike them the
|
||||
# gateway is NOT the client here (see the no-vhost note at the top), so
|
||||
# sharing the netns is what lets the store bind the host's own addresses
|
||||
# rather than a convenience for nginx.
|
||||
privateNetwork = false;
|
||||
in
|
||||
{
|
||||
# One service, two namespaces, and the split decides who may set what.
|
||||
|
|
@ -3444,11 +3450,7 @@ in
|
|||
containers.${cfg.machine} = {
|
||||
autoStart = true;
|
||||
ephemeral = false;
|
||||
# Shared host netns, like every sibling swarm container. Unlike them the
|
||||
# gateway is NOT the client here (see the no-vhost note at the top), so
|
||||
# sharing the netns is what lets the store bind the host's own addresses
|
||||
# rather than a convenience for nginx.
|
||||
privateNetwork = false;
|
||||
inherit privateNetwork;
|
||||
|
||||
# Only material an operator has to be able to back up crosses the
|
||||
# boundary — the store's identity and its seal. The raft state
|
||||
|
|
@ -3513,6 +3515,7 @@ in
|
|||
{ config, ... }:
|
||||
{
|
||||
imports = [
|
||||
../container-modules/swarm-container.nix
|
||||
(import ../container-modules/swarm-container-resolver.nix {
|
||||
inherit (networkCfg) bridgeIp;
|
||||
# The forwarder resolves two swarm names of its own — the
|
||||
|
|
@ -3539,14 +3542,7 @@ in
|
|||
})
|
||||
];
|
||||
|
||||
system.stateVersion = "26.05";
|
||||
|
||||
# Shares the host netns, so its own firewall.service would rewrite
|
||||
# the HOST ruleset at every boot. The host firewall owns filtering.
|
||||
networking.firewall.enable = false;
|
||||
# The resolver unit imported above owns /etc/resolv.conf; leaving
|
||||
# resolvconf on would let host-tracking regenerate it empty.
|
||||
networking.resolvconf.enable = lib.mkForce false;
|
||||
services.hyperhive.swarmContainer = { inherit privateNetwork; };
|
||||
|
||||
# `${tokenGroup}` takes whatever gid this container allocates —
|
||||
# nothing outside reads it. `${tpmGroup}` must take the PINNED one,
|
||||
|
|
|
|||
Loading…
Reference in a new issue