deploy: move the wireguard mesh out of the namespace hives read
`swarm.*` is what a hive needs to be a *client* of the swarm; the mesh is none of it. A peer needs this host's `wireguardEndpoint` -- the roster entry in swarm.nix, which stays -- and nothing about the interface this host brings up. The module already said so: "plain host networking that a machine which runs no hive at all still needs." All five options move, so the namespace relocates rather than splitting. `listenPort` is the one that reads the other way: it is what this host *binds*, while the port a peer *dials* lives inside `wireguardEndpoint`. Declared in swarm-wireguard.nix under the `deploy.*` path, following swarm-victorialogs.nix; deploy.nix carries only the renames, per its own "a single file to delete when the deprecation window closes". Deliberately NOT added to deploy.nix's own options block: every entry there is a swarm service this host deploys, and the mesh is host networking. hivectl/src/wg.rs generates the config snippet an operator pastes, so it moves too -- otherwise the tool's own output trips the deprecation warning. module-eval gains a case that configures a host through the OLD path and asserts the rendered wg-hive interface, because the new path evaluates fine without the shim: dropping it reads as a clean tree.
This commit is contained in:
parent
c7c221baeb
commit
368f5d82aa
10 changed files with 85 additions and 27 deletions
|
|
@ -148,6 +148,34 @@ in
|
|||
[ "services" "hyperhive" "tls" "leafValidityDays" ]
|
||||
[ "services" "hyperhive" "deploy" "hive-controller" "tls" "leafValidityDays" ]
|
||||
)
|
||||
|
||||
# The WireGuard mesh, whole. Unlike every rename above this one moves a
|
||||
# namespace rather than a toggle: nothing under it is a fact another hive
|
||||
# reads. A peer needs this host's `wireguardEndpoint` — the roster entry
|
||||
# in ./swarm.nix, which stays — and nothing about the interface this host
|
||||
# brings up. `listenPort` moves for the same reason and is easy to read
|
||||
# the other way: it is what this host *binds*, while the port a peer
|
||||
# *dials* is the one inside `wireguardEndpoint`.
|
||||
(lib.mkRenamedOptionModule
|
||||
[ "services" "hyperhive" "swarm" "wireguard" "enable" ]
|
||||
[ "services" "hyperhive" "deploy" "wireguard" "enable" ]
|
||||
)
|
||||
(lib.mkRenamedOptionModule
|
||||
[ "services" "hyperhive" "swarm" "wireguard" "privateKeyFile" ]
|
||||
[ "services" "hyperhive" "deploy" "wireguard" "privateKeyFile" ]
|
||||
)
|
||||
(lib.mkRenamedOptionModule
|
||||
[ "services" "hyperhive" "swarm" "wireguard" "address" ]
|
||||
[ "services" "hyperhive" "deploy" "wireguard" "address" ]
|
||||
)
|
||||
(lib.mkRenamedOptionModule
|
||||
[ "services" "hyperhive" "swarm" "wireguard" "listenPort" ]
|
||||
[ "services" "hyperhive" "deploy" "wireguard" "listenPort" ]
|
||||
)
|
||||
(lib.mkRenamedOptionModule
|
||||
[ "services" "hyperhive" "swarm" "wireguard" "persistentKeepalive" ]
|
||||
[ "services" "hyperhive" "deploy" "wireguard" "persistentKeepalive" ]
|
||||
)
|
||||
];
|
||||
|
||||
# ⚠️ `deploy.forgejo` is declared in ./hive-ci.nix, not here, and it is the
|
||||
|
|
|
|||
Loading…
Reference in a new issue