module-eval: read the services-leaf narrowing off a forge host
`checks.module-eval-core-toggle` is red on main: "a gateway's services leaf asks for only the swarm names that host fronts" read its leaf request off `bare`, on the premise that `bare` fronts forge. That was true where the property was written, before978164dc(#4705) defaulted `deploy.forgejo.enable` to false. The two merged in sequence, and on main `bare` renders only the `_` and `h1.t.local` vhosts, so its `localServiceDomains` is [] and the script carries `alt_names=''`, never `alt_names=forge.t.local`. The narrowing itself is right: a host that runs no forge fronts no swarm name and asks for no services leaf. Only the fixture was stale. The property now reads a hive with `deploy.forgejo.enable = true`, whose request is `common_name=forge.t.local alt_names=forge.t.local` while `auth.t.local` stays in the swarm-wide set. The renewal timer from0649673eis not involved: the check's derivation is identical at0649673eand at its parent, anded2ec52freplayed onto978164dc^ holds while replayed onto978164dcit fails. Refs #4587
This commit is contained in:
parent
3202cde704
commit
1948e7ad23
1 changed files with 7 additions and 6 deletions
|
|
@ -205,15 +205,16 @@ let
|
||||||
}
|
}
|
||||||
{
|
{
|
||||||
# A leaf is a key that can SERVE every name in it, so the names it
|
# A leaf is a key that can SERVE every name in it, so the names it
|
||||||
# asks for are that key's blast radius. `bare` fronts forge and
|
# asks for are that key's blast radius. The forge's host fronts forge
|
||||||
# nothing else; the last conjunct is the control, since `auth.t.local`
|
# and nothing else; the last conjunct is the control, since
|
||||||
# is in the swarm's set and an unnarrowed request would carry it here
|
# `auth.t.local` is in the swarm's set and an unnarrowed request would
|
||||||
# too.
|
# carry it here too.
|
||||||
name = "a gateway's services leaf asks for only the swarm names that host fronts";
|
name = "a gateway's services leaf asks for only the swarm names that host fronts";
|
||||||
ok =
|
ok =
|
||||||
let
|
let
|
||||||
s = bare.services.hyperhive.swarm.serviceDomains;
|
forgeHere = hive { deploy.forgejo.enable = true; };
|
||||||
u = bare.systemd.services.swarm-services-cert.script;
|
s = forgeHere.services.hyperhive.swarm.serviceDomains;
|
||||||
|
u = forgeHere.systemd.services.swarm-services-cert.script;
|
||||||
in
|
in
|
||||||
lib.hasInfix "alt_names=forge.t.local" u
|
lib.hasInfix "alt_names=forge.t.local" u
|
||||||
&& !(lib.hasInfix "auth.t.local" u)
|
&& !(lib.hasInfix "auth.t.local" u)
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue