nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
`services.hyperhive.enable` and `services.hyperhive.c0re.enable` are gone. One switch, `services.hyperhive.deploy.hive-controller.enable` (default false, as the old toggle was), now gates hive-c0re and hive-priv. Both old paths are `mkRenamedOptionModule` shims in deploy.nix, so a host config that still sets either evaluates as before and gets a rename warning. Every other read of the old toggle is resolved, including the 29 made through the `hyperhiveCfg`/`hiveCfg` aliases: - Dropped: each swarm service and its glue keeps only its own deploy toggle (authelia, bao and its PKI glue, grafana, victorialogs, victoriametrics, the secret publisher, swarm-ca, the OIDC client rows, the controller/nats/matrix-ctl/publisher/services-issuer identities), the forge, and the `domain` deprecation warning. - To deploy.hive-controller.enable: the queue-agent credential reader and its assertion, which feed hive-c0re and write under its state dir, plus their policy-order entry; the network identity assertions; hive-tls's two writes into hive-c0re's environment. - hive-tls runs where the gateway runs self-signed (`gateway.enable && useSelfSigned`), not on every host. - The matrix appservice-token reader and its assertion stay on `deploy.matrix.enable` plus their client-identity checks. They read deploy.matrix's token file and registration script; their deploy.bao inputs are the client-half options a hive sets to read a store it does not run, so gating on deploy.bao.enable would drop the tested remote-reader case. - The `hiveName` assertion moves from hive-network.nix to hyperhive.nix and fires wherever the hive, the store or the homeserver runs: each turns the name into an identifier with no fallback. On a host with `deploy.allSwarmServices` and no hive, the documented services-host recipe, authelia, bao, grafana, victorialogs, victoriametrics, the OIDC client rows and the hive CA now render; before, the old toggle being off left them out. Refs #4500
This commit is contained in:
parent
ed2ec52fe5
commit
3202cde704
43 changed files with 292 additions and 162 deletions
|
|
@ -37,12 +37,11 @@ let
|
|||
|
||||
# The host-managed hive CA is the trust anchor for self-signed mode.
|
||||
# It is only stood up when the gateway actually serves a self-signed
|
||||
# cert: the gateway must be in self-signed mode. `domain` is required
|
||||
# (asserted in hive-network.nix), so the leaf SANs always have a
|
||||
# domain to derive from. The self-signed condition is the gateway
|
||||
# module's single source of truth (`gateway.useSelfSigned`): true when
|
||||
# neither an operator cert (`tls.certDir`) nor ACME is set.
|
||||
active = hyperhiveCfg.enable && gatewayCfg.useSelfSigned;
|
||||
# cert: the gateway must run here and be in self-signed mode. The
|
||||
# self-signed condition is the gateway module's single source of truth
|
||||
# (`gateway.useSelfSigned`): true when neither an operator cert
|
||||
# (`tls.certDir`) nor ACME is set.
|
||||
active = gatewayCfg.enable && gatewayCfg.useSelfSigned;
|
||||
|
||||
# How this hive's CA comes into existence when it is missing — and it
|
||||
# is one of exactly two things, chosen by config rather than by what
|
||||
|
|
@ -1022,7 +1021,14 @@ in
|
|||
# bundle. It is the ANCHOR bundle rather than `ca.pem` for the reason
|
||||
# spelled out where the bundle is written above; no key path is ever
|
||||
# exposed (an agent that could read one could mint trusted certs).
|
||||
systemd.services.hive-c0re.environment.HIVE_TLS_CA_PATH = "${cfg.stateDir}/trust-bundle.pem";
|
||||
#
|
||||
# ⚠️ Every line here that names another daemon's unit is gated on that
|
||||
# daemon's own enable: the gateway also runs on hosts with no hive and no
|
||||
# controller, and defining an environment key on a unit that does not
|
||||
# exist CREATES a unit fragment for it — inert (no `ExecStart`, empty
|
||||
# `wantedBy`, never activated), and it evaluates and builds clean.
|
||||
systemd.services.hive-c0re.environment.HIVE_TLS_CA_PATH =
|
||||
lib.mkIf hyperhiveCfg.deploy.hive-controller.enable "${cfg.stateDir}/trust-bundle.pem";
|
||||
|
||||
# The same anchor, named for the swarm-queue clients that need it when
|
||||
# they mint a token from authelia over TLS. Declared HERE, beside the
|
||||
|
|
@ -1038,18 +1044,11 @@ in
|
|||
# variable name. The anchor was never missing; nothing pointed the queue
|
||||
# client at it.
|
||||
#
|
||||
# Set unconditionally within this module's `active` guard, exactly like
|
||||
# the line above: where there is no hive CA this module contributes
|
||||
# nothing at all, and the clients then fall back to the platform roots —
|
||||
# which is correct for a swarm fronted by a public certificate.
|
||||
systemd.services.hive-c0re.environment.HIVE_C0RE_OIDC_CA_FILE = "${cfg.stateDir}/trust-bundle.pem";
|
||||
# ⚠️ Gated, where the hive-c0re line above is not, and the asymmetry is
|
||||
# the point: hive-c0re runs on every hive, the controller runs on one.
|
||||
# Defining an environment key on a unit that does not exist CREATES a
|
||||
# unit fragment for it — inert (no `ExecStart`, empty `wantedBy`, never
|
||||
# activated) but present on every non-controller hive with a CA. Caught
|
||||
# in review on this PR; it evaluates and builds clean either way, which
|
||||
# is exactly why it needed a reviewer rather than a check.
|
||||
# Where there is no hive CA this module contributes nothing at all, and
|
||||
# the clients then fall back to the platform roots — which is correct for
|
||||
# a swarm fronted by a public certificate.
|
||||
systemd.services.hive-c0re.environment.HIVE_C0RE_OIDC_CA_FILE =
|
||||
lib.mkIf hyperhiveCfg.deploy.hive-controller.enable "${cfg.stateDir}/trust-bundle.pem";
|
||||
systemd.services.swarm-controller.environment.SWARM_CONTROLLER_OIDC_CA_FILE =
|
||||
lib.mkIf hyperhiveCfg.deploy.swarm-controller.enable "${cfg.stateDir}/trust-bundle.pem";
|
||||
};
|
||||
|
|
|
|||
Loading…
Reference in a new issue