diff --git a/nix/module-eval/core-toggle.nix b/nix/module-eval/core-toggle.nix index 53aecc1e..7a6a7827 100644 --- a/nix/module-eval/core-toggle.nix +++ b/nix/module-eval/core-toggle.nix @@ -205,15 +205,16 @@ let } { # A leaf is a key that can SERVE every name in it, so the names it - # asks for are that key's blast radius. `bare` fronts forge and - # nothing else; the last conjunct is the control, since `auth.t.local` - # is in the swarm's set and an unnarrowed request would carry it here - # too. + # asks for are that key's blast radius. The forge's host fronts forge + # and nothing else; the last conjunct is the control, since + # `auth.t.local` is in the swarm's set and an unnarrowed request would + # carry it here too. name = "a gateway's services leaf asks for only the swarm names that host fronts"; ok = let - s = bare.services.hyperhive.swarm.serviceDomains; - u = bare.systemd.services.swarm-services-cert.script; + forgeHere = hive { deploy.forgejo.enable = true; }; + s = forgeHere.services.hyperhive.swarm.serviceDomains; + u = forgeHere.systemd.services.swarm-services-cert.script; in lib.hasInfix "alt_names=forge.t.local" u && !(lib.hasInfix "auth.t.local" u)