deploy: move the SSO provider toggle
The largest of these moves: sixteen references spelled through `let` aliases across eight modules, plus eight more spelled as a path, plus five documentation pages. authelia is also the clearest case for why the two namespaces exist. `swarm.authelia.url` is needed by *every* hive in the swarm — it says where to send a browser to authenticate — while running the container is the business of exactly one host. The client half and the server half were sharing a namespace whose whole contract is "identical everywhere", and only one of them could honour it. `swarm.authelia.oidc.clients` stays where it is for the same reason: several modules register a client there, gated on authelia running here, and the registry itself is what the service *is* rather than a decision about this machine. One sweep note worth recording: a grep for `swarm.authelia.enable` misses `swarmCfg.authelia.enable`, because the prefix is whatever the reading file bound. Grepping the suffix `.authelia.enable` finds both, and found a reference in swarm.nix that the path-shaped pattern did not.
This commit is contained in:
parent
0b7357d4b8
commit
37ca7676d6
16 changed files with 77 additions and 50 deletions
|
|
@ -231,9 +231,7 @@ in
|
|||
clientSecretFile = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.str;
|
||||
default =
|
||||
if
|
||||
config.services.hyperhive.swarm.authelia.enable && config.services.hyperhive.hiveName != null
|
||||
then
|
||||
if config.services.hyperhive.deploy.authelia && config.services.hyperhive.hiveName != null then
|
||||
"${config.services.hyperhive.swarm.authelia.hostClientSecretDir}/"
|
||||
+ "${config.services.hyperhive.swarm.authelia.hiveClientPrefix}${config.services.hyperhive.hiveName}.secret"
|
||||
else
|
||||
|
|
@ -284,6 +282,7 @@ in
|
|||
let
|
||||
otel = config.services.hyperhive.otel;
|
||||
autheliaCfg = config.services.hyperhive.swarm.authelia;
|
||||
deployCfg = config.services.hyperhive.deploy;
|
||||
swarmOtelCfg = config.services.hyperhive.swarm.otel;
|
||||
hiveName = config.services.hyperhive.hiveName;
|
||||
listen = "${config.services.hyperhive.network.bridgeIp}:${toString otel.collector.port}";
|
||||
|
|
@ -580,8 +579,8 @@ in
|
|||
# Only when the minting container is on THIS host. Elsewhere the file
|
||||
# is operator-provided and there is no local unit to order against —
|
||||
# naming one that does not exist orders nothing, silently.
|
||||
after = lib.optional autheliaCfg.enable "container@${autheliaCfg.machine}.service";
|
||||
requires = lib.optional autheliaCfg.enable "container@${autheliaCfg.machine}.service";
|
||||
after = lib.optional deployCfg.authelia "container@${autheliaCfg.machine}.service";
|
||||
requires = lib.optional deployCfg.authelia "container@${autheliaCfg.machine}.service";
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
RemainAfterExit = true;
|
||||
|
|
|
|||
Loading…
Reference in a new issue