nix: move the remaining service containers onto the swarm-container module
hive-ci, hive-forge, hive-matrix, swarm-authelia, swarm-bao, swarm-grafana, swarm-nats, swarm-otel and swarm-victorialogs now import ./swarm-container.nix and drop their own copies of the stateVersion, firewall and resolvconf lines. Each binds privateNetwork once in its top-level let and passes it to both the host attr and the in-container option, as swarm-victoriametrics already does. hive-forge (25.11) and swarm-otel (the host's value) keep their own stateVersion over the module's mkDefault. hive-ci sets privateNetwork = true and writesOwnResolvConf = false, which leaves its firewall and resolvconf on, as before. hive-matrix keeps its useHostResolvConf override and static resolv.conf; its resolvconf mkForce now comes from the module default. Every container's system.build.toplevel drvPath and host-side attrs evaluate identical to the parent commit. module-eval-swarm-services-switch gains a fixture with all ten service containers and checks that each one's in-container privateNetwork equals its host-side value, that the nine on the host netns run no firewall or resolvconf, that hive-ci keeps both, and that hive-forge keeps its pinned stateVersion. Refs #3773
This commit is contained in:
parent
53d9ebdede
commit
10d579ecaf
10 changed files with 133 additions and 135 deletions
|
|
@ -94,6 +94,15 @@ let
|
|||
deploy.forgejo.enable = true;
|
||||
deploy.forgejo.mirrors = [ aMirror ];
|
||||
};
|
||||
|
||||
# Every service container at once: the services-only host plus the CI
|
||||
# runner, the one container on a netns of its own.
|
||||
serviceContainersWithCi = hive {
|
||||
deploy.hive-controller.enable = false;
|
||||
deploy.allSwarmServices = true;
|
||||
deploy.forgejo.ci.enable = true;
|
||||
};
|
||||
serviceContainers = serviceContainersWithCi.containers;
|
||||
cases = [
|
||||
{
|
||||
# `lib.all` over an empty set holds vacuously, so the roster is counted
|
||||
|
|
@ -186,19 +195,46 @@ let
|
|||
&& !(s ? swarm-bao-queue-agent);
|
||||
}
|
||||
{
|
||||
# Both values come from ../container-modules/swarm-container.nix. Read
|
||||
# through the metrics store: nothing else in this suite evaluates that
|
||||
# container's config.
|
||||
# The in-container option drives the container's firewall, and host
|
||||
# `false` with container `true` would let the container's
|
||||
# firewall.service rewrite the HOST ruleset. Counted first so a fixture
|
||||
# that lost a container can't pass by comparing fewer of them.
|
||||
name = "every service container restates its host-side privateNetwork";
|
||||
ok =
|
||||
lib.length (lib.attrNames serviceContainers) == 10
|
||||
&& lib.all (
|
||||
c: c.privateNetwork == (c.config.services.hyperhive.swarmContainer.privateNetwork or null)
|
||||
) (lib.attrValues serviceContainers);
|
||||
}
|
||||
{
|
||||
# Both values come from ../container-modules/swarm-container.nix.
|
||||
name = "a service container on the host netns runs no firewall or resolvconf of its own";
|
||||
ok =
|
||||
let
|
||||
c = swarmServicesOnly.containers.swarm-victoriametrics.config;
|
||||
shared = lib.filter (c: !c.privateNetwork) (lib.attrValues serviceContainers);
|
||||
in
|
||||
!c.networking.firewall.enable && !c.networking.resolvconf.enable;
|
||||
lib.length shared == 9
|
||||
&& lib.all (
|
||||
c: !c.config.networking.firewall.enable && !c.config.networking.resolvconf.enable
|
||||
) shared;
|
||||
}
|
||||
{
|
||||
# The `privateNetwork = true` and `writesOwnResolvConf = false` arms:
|
||||
# NixOS enables both by default, so the module must leave them alone.
|
||||
name = "a service container on a netns of its own keeps its firewall and resolvconf";
|
||||
ok =
|
||||
let
|
||||
c = serviceContainers.hive-ci.config;
|
||||
in
|
||||
c.networking.firewall.enable && c.networking.resolvconf.enable;
|
||||
}
|
||||
{
|
||||
name = "a service container that sets no stateVersion of its own is on 26.05";
|
||||
ok = swarmServicesOnly.containers.swarm-victoriametrics.config.system.stateVersion == "26.05";
|
||||
ok = serviceContainers.swarm-victoriametrics.config.system.stateVersion == "26.05";
|
||||
}
|
||||
{
|
||||
name = "a service container that pins its own stateVersion keeps it";
|
||||
ok = serviceContainers.hive-forge.config.system.stateVersion == "25.11";
|
||||
}
|
||||
{
|
||||
# An operator's explicit `false` beats every `mkDefault` assertion,
|
||||
|
|
|
|||
Loading…
Reference in a new issue