nix: move the remaining service containers onto the swarm-container module
hive-ci, hive-forge, hive-matrix, swarm-authelia, swarm-bao, swarm-grafana, swarm-nats, swarm-otel and swarm-victorialogs now import ./swarm-container.nix and drop their own copies of the stateVersion, firewall and resolvconf lines. Each binds privateNetwork once in its top-level let and passes it to both the host attr and the in-container option, as swarm-victoriametrics already does. hive-forge (25.11) and swarm-otel (the host's value) keep their own stateVersion over the module's mkDefault. hive-ci sets privateNetwork = true and writesOwnResolvConf = false, which leaves its firewall and resolvconf on, as before. hive-matrix keeps its useHostResolvConf override and static resolv.conf; its resolvconf mkForce now comes from the module default. Every container's system.build.toplevel drvPath and host-side attrs evaluate identical to the parent commit. module-eval-swarm-services-switch gains a fixture with all ten service containers and checks that each one's in-container privateNetwork equals its host-side value, that the nine on the host netns run no firewall or resolvconf, that hive-ci keeps both, and that hive-forge keeps its pinned stateVersion. Refs #3773
This commit is contained in:
parent
53d9ebdede
commit
10d579ecaf
10 changed files with 133 additions and 135 deletions
|
|
@ -242,6 +242,19 @@ let
|
|||
# grants it (./swarm-bao.nix), so the daily timer below has two weeks of
|
||||
# retries before it lapses.
|
||||
leafRenewSeconds = 360 * 3600;
|
||||
|
||||
# Shared host netns, like every sibling swarm container.
|
||||
#
|
||||
# ⚠️ Which is exactly why the server below must refuse everyone
|
||||
# until the callout responder exists: the queue is on the host's
|
||||
# own loopback, in reach of every process there and every sibling
|
||||
# on this netns, and each remote hive in a multi-host swarm dials
|
||||
# it directly. An unauthenticated interim state would be a hole
|
||||
# rather than a rough edge.
|
||||
#
|
||||
# Not agent containers, though: they have a netns of their own and
|
||||
# the bridge firewall does not open this port.
|
||||
privateNetwork = false;
|
||||
in
|
||||
{
|
||||
# The swarm's message queue: one NATS server, reached by every hive at
|
||||
|
|
@ -723,18 +736,7 @@ in
|
|||
# Journal files on the host, not inside the container: nixpkgs hardcodes
|
||||
# --link-journal=try-guest, and EXTRA_NSPAWN_FLAGS expands after it.
|
||||
extraFlags = [ "--link-journal=host" ];
|
||||
# Shared host netns, like every sibling swarm container.
|
||||
#
|
||||
# ⚠️ Which is exactly why the server below must refuse everyone
|
||||
# until the callout responder exists: the queue is on the host's
|
||||
# own loopback, in reach of every process there and every sibling
|
||||
# on this netns, and each remote hive in a multi-host swarm dials
|
||||
# it directly. An unauthenticated interim state would be a hole
|
||||
# rather than a rough edge.
|
||||
#
|
||||
# Not agent containers, though: they have a netns of their own and
|
||||
# the bridge firewall does not open this port.
|
||||
privateNetwork = false;
|
||||
inherit privateNetwork;
|
||||
# The public trust bundle (empty when the gateway is not self-signed)
|
||||
# and the queue's own TLS leaf, both read-only.
|
||||
bindMounts = caTrust.bindMount // {
|
||||
|
|
@ -747,6 +749,7 @@ in
|
|||
{ ... }:
|
||||
{
|
||||
imports = [
|
||||
../container-modules/swarm-container.nix
|
||||
(import ../container-modules/swarm-container-resolver.nix {
|
||||
inherit (networkCfg) bridgeIp;
|
||||
# The responder introspects authelia BY NAME on every auth
|
||||
|
|
@ -758,17 +761,7 @@ in
|
|||
caBundleModule
|
||||
];
|
||||
|
||||
system.stateVersion = "26.05";
|
||||
|
||||
# Shared host netns: this container's own firewall.service
|
||||
# would rewrite the HOST ruleset at every boot. The host
|
||||
# firewall owns all filtering.
|
||||
networking.firewall.enable = false;
|
||||
# resolvconf stays off because the resolver unit imported above
|
||||
# owns /etc/resolv.conf. Leaving it on would let host-tracking
|
||||
# regenerate the file empty, since the host's copy does not
|
||||
# cross the boundary after start.
|
||||
networking.resolvconf.enable = lib.mkForce false;
|
||||
services.hyperhive.swarmContainer = { inherit privateNetwork; };
|
||||
|
||||
services.nats = {
|
||||
enable = true;
|
||||
|
|
|
|||
Loading…
Reference in a new issue