swarm-otel: collect only the units the swarm's services declare
The journald receiver was configured with a directory and no filter, so the swarm's log store received every unit on the host that runs the collector. On a hive whose services live on a workstation that includes the operator's desktop session, in a store every swarm operator can read. The receiver has no system-only switch and its `matches` field is an allowlist too, so what the swarm collects has to be stated rather than excluded. Each service module names its own units: a service that is not running contributes nothing, and one added later arrives declared. An empty list is fail-open — the receiver renders no filter at all and reads everything — so it is asserted against.
This commit is contained in:
parent
8879225fa4
commit
4336436457
11 changed files with 145 additions and 14 deletions
|
|
@ -420,6 +420,14 @@ in
|
|||
};
|
||||
|
||||
config = lib.mkIf config.services.hyperhive.enable {
|
||||
# Same principle as the vhost below — this service's own surface lives
|
||||
# with the service. The SSO source is named alongside forgejo because
|
||||
# its failure mode is a login that silently falls back, not an error.
|
||||
services.hyperhive.swarm.otel.journaldUnits = [
|
||||
"forgejo"
|
||||
"forgejo-sso-source"
|
||||
];
|
||||
|
||||
# This service's own gateway surface: the vhost that fronts it and
|
||||
# the name the hive resolver answers for. Declared here rather than
|
||||
# in the gateway so the forge's public face lives with the forge —
|
||||
|
|
|
|||
Loading…
Reference in a new issue