swarm-controller: own the swarm-wide forge objects; hive-c0re stops creating them
The orgs agent-configs/internal/agents (plus mirror owners), the operators team in agents and agent-configs, the pull-mirrors, internal/docs, internal/knowledge (public, README-seeded) and the agent-configs org avatar are one set per forge. hive-c0re ensured them in its boot sweep, as the core admin, and only on the hive co-located with the forge container. swarm-controller now reconciles them at start and every 5 minutes (forge/objects.rs: observe -> pure plan -> apply). A failed object logs a warn line plus a pass summary and is retried next tick. create_repo ensures the agent-configs org and its operators team first, so a config repo's merge gate never depends on the periodic pass having run. hive-c0re drops ensure_org, SEEDED_ORGS, ensure_mirrors/ensure_mirror_repo, ensure_operators_team, ensure_shared_docs_repo, ensure_knowledge_repo/ set_repo_public, seed_readme, ensure_config_org_avatar and the one-shot knowledge::remove_webhook cleanup, with their now-unused helpers. nix: the mirror list moves from the hive-c0re unit (HYPERHIVE_FORGE_MIRRORS) to the swarm-controller unit (SWARM_CONTROLLER_FORGE_MIRRORS), with an eval warning when mirrors are declared on a host that runs no controller. c0re.orgAvatarPng is renamed to deploy.swarm-controller.configOrgAvatarPng. Refs #3782
This commit is contained in:
parent
85ba45b2de
commit
20419ccd41
18 changed files with 1456 additions and 822 deletions
|
|
@ -190,6 +190,13 @@ let
|
|||
# Same `%d` shape as the queue secret above — root reads the plaintext
|
||||
# at unit start, the daemon's own user sees a 0400 copy.
|
||||
SWARM_CONTROLLER_FORGE_TOKEN_FILE = "%d/forge-token";
|
||||
# `agent-configs` org avatar for the forge-objects pass
|
||||
# (`forge/objects.rs`). Only meaningful with forge access, hence here.
|
||||
SWARM_CONTROLLER_CONFIG_ORG_AVATAR_PNG =
|
||||
if deployCfg.swarm-controller.configOrgAvatarPng != null then
|
||||
"${deployCfg.swarm-controller.configOrgAvatarPng}"
|
||||
else
|
||||
"${config.services.hyperhive.c0re.assets}/share/hyperhive/branding/agent-configs.png";
|
||||
};
|
||||
|
||||
# How the forge must address this controller to deliver a swarm-wide
|
||||
|
|
@ -311,6 +318,12 @@ in
|
|||
hostUnit = true;
|
||||
enable = deployCfg.swarm-controller.enable;
|
||||
})
|
||||
# The avatar moved with the forge-objects pass that uploads it: from
|
||||
# hive-c0re's boot sweep to this daemon.
|
||||
(lib.mkRenamedOptionModule
|
||||
[ "services" "hyperhive" "c0re" "orgAvatarPng" ]
|
||||
[ "services" "hyperhive" "deploy" "swarm-controller" "configOrgAvatarPng" ]
|
||||
)
|
||||
];
|
||||
|
||||
options.services.hyperhive.swarm.controller = {
|
||||
|
|
@ -498,6 +511,20 @@ in
|
|||
'';
|
||||
};
|
||||
|
||||
configOrgAvatarPng = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.path;
|
||||
default = null;
|
||||
description = ''
|
||||
PNG uploaded once as the `agent-configs` Forgejo org's avatar by
|
||||
the controller's swarm-wide forge-objects pass (one-shot,
|
||||
marker-guarded — delete `forge-config-org-avatar-set` under the
|
||||
controller's state directory to force a re-upload after changing
|
||||
this). Defaults (`null`) to the bundled `agent-configs.png` from
|
||||
{option}`services.hyperhive.c0re.assets`. Set this to override just
|
||||
the org avatar without replacing the whole `assets` package.
|
||||
'';
|
||||
};
|
||||
|
||||
forgeTokenFile = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.str;
|
||||
# Forge's own delivery path when the forge runs here, since nothing
|
||||
|
|
|
|||
Loading…
Reference in a new issue