docs: name options by the path an operator can set, not by cfg.*
`cfg` is whatever the reading module bound it to. It does not exist in a NixOS configuration, so a sentence naming an option as `cfg.<name>` is correct about behaviour and unusable as an instruction — the reader has to go find the real path. The four sites in docs/networking/gateway.md this was filed for: cfg.sshPort -> services.hyperhive.swarm.forge.sshPort cfg.dashboardPort -> services.hyperhive.c0re.dashboardPort cfg.frontend (x2) -> services.hyperhive.c0re.frontend Sweeping docs/ for the pattern rather than the ticket's line numbers found five more, in four other files: approvals.md cfg.hyperhiveFlake -> services.hyperhive.c0re.hyperhiveFlake matrix.md cfg.registrationTokenFile -> services.hyperhive.deploy.matrix.registrationTokenFile matrix.md cfg.gatewayHost -> services.hyperhive.swarm.matrix.gatewayHost conventions.md cfg.dashboardPort -> services.hyperhive.c0re.dashboardPort gotchas.md cfg.dashboardPort -> services.hyperhive.c0re.dashboardPort matrix.md is the clearest case for doing this at all: its two `cfg.` references resolve to *different* option trees — `deploy.matrix` and `swarm.matrix` — so the shorthand is ambiguous even within one file. Each path is read off the `mkOption` that declares it plus the `options.services.hyperhive.*` root it sits under, with the indentation checked so a nested block cannot have been missed. `cfg.frontend` is declared in hive-c0re, not the gateway: the gateway module binds `cfg = config.services.hyperhive.gateway`, which has no `frontend`. Deliberately unchanged: docs/networking/snapshot-store.md:136, where `cfg.port` sits inside a ```nix block quoting module source. `cfg` is correct there, and rewriting it would make the snippet wrong. Closes #4193.
This commit is contained in:
parent
f918cea957
commit
3f878408f0
5 changed files with 10 additions and 9 deletions
|
|
@ -87,7 +87,7 @@ Per-vhost timeouts + body-size limits live in the location blocks:
|
|||
- matrix `/_matrix/` (tuwunel): `client_max_body_size 50M` (media uploads), `proxy_read_timeout 1h` (long-poll `/sync`), CORS `*` (federation + cross-origin clients), `proxyWebsockets = true`.
|
||||
- per-agent `/agent/<name>/`: `proxy_read_timeout 1d` (long-lived SSE / WebSocket dashboards), `proxyWebsockets = true`, `X-Forwarded-Prefix` set so the harness can build absolute URLs when relative isn't enough.
|
||||
|
||||
SSH for forge stays direct on `cfg.sshPort` — separate listener protocol, not HTTP-over-nginx.
|
||||
SSH for forge stays direct on `services.hyperhive.swarm.forge.sshPort` — separate listener protocol, not HTTP-over-nginx.
|
||||
|
||||
## Per-agent unix-socket upstream
|
||||
|
||||
|
|
@ -292,7 +292,7 @@ TLS (see [TLS modes](#tls-modes) above).
|
|||
Every agent hashes into the same port range (no special case), so
|
||||
one range opening covers every container.
|
||||
|
||||
The dashboard port (`cfg.dashboardPort`, default 7000) is *not*
|
||||
The dashboard port (`services.hyperhive.c0re.dashboardPort`, default 7000) is *not*
|
||||
listed in either case — it binds `127.0.0.1` only, so a firewall
|
||||
hole would be a no-op. Remote dashboard access flows through the
|
||||
gateway. Operators who opt out of the gateway lose external
|
||||
|
|
@ -457,12 +457,12 @@ store path baked in at hive-c0re build time, and c0re (writing
|
|||
so they see the same store.
|
||||
|
||||
**Graceful degradation**: if `HIVE_AGENT_FRONTEND_DIR` is empty or
|
||||
unset (for example a build that predates `cfg.frontend`), each agent gets the
|
||||
unset (for example a build that predates `services.hyperhive.c0re.frontend`), each agent gets the
|
||||
legacy single-proxy block and nginx forwards all traffic to the agent
|
||||
daemon as before.
|
||||
|
||||
**`extraFiles`**: per-agent `hyperhive.frontend.extraFiles` are in
|
||||
`mergedDist`, not in the base `cfg.frontend` dist. They're not under
|
||||
`mergedDist`, not in the base `services.hyperhive.c0re.frontend` dist. They're not under
|
||||
the nix-store `alias` path, so requests for them fall through
|
||||
`try_files` to `@<name>_dynamic`, and the agent daemon serves them
|
||||
as before.
|
||||
|
|
|
|||
Loading…
Reference in a new issue