swarm-otel: collect only the units the swarm's services declare

The journald receiver was configured with a directory and no filter, so
the swarm's log store received every unit on the host that runs the
collector. On a hive whose services live on a workstation that includes
the operator's desktop session, in a store every swarm operator can read.

The receiver has no system-only switch and its `matches` field is an
allowlist too, so what the swarm collects has to be stated rather than
excluded. Each service module names its own units: a service that is not
running contributes nothing, and one added later arrives declared.

An empty list is fail-open — the receiver renders no filter at all and
reads everything — so it is asserted against.
This commit is contained in:
atlas 2026-08-24 21:54:45 +02:00 committed by mara
commit 4336436457
11 changed files with 145 additions and 14 deletions

View file

@ -115,6 +115,18 @@ in
# file's `let` and are not option surface.
services.hyperhive.gateway.lib = vhostLib;
# Every request to every hyperhive service passes through here, so this
# is the one unit that can say a service was unreachable rather than
# merely quiet. Named even on hives that run no swarm collector: the
# option is inert unless one is collecting on this host.
#
# dnsmasq alongside it for the same reason one level down: a name that
# stops resolving presents as every client timing out at once.
services.hyperhive.swarm.otel.journaldUnits = [
"nginx"
"dnsmasq"
];
assertions = [
{
assertion = !(cfg.tls.acme.enable && cfg.tls.certDir != null);