swarm-bao: stop linking the container's journal onto the host

--link-journal=host bind-mounts a host directory journald never
writes into for this container (empty, root:nogroup, confirmed on
the live host — #4527). Dropping it falls back to nixpkgs' default
--link-journal=try-guest, the same shape every agent container
already uses, so the in-container collector's journald receiver
(directory = /var/log/journal) now reads a journal that is actually
written.

merge stays true and services.hyperhive.swarm.otel.journaldUnits is
untouched so this deploy changes exactly one thing; comments that
described the old host-linked shape are rewritten to match.

Adds a module-eval assertion (bao-otel-collector.nix) that the
container's extraFlags never re-add --link-journal=host.

Refs #4527, #4499.
This commit is contained in:
atlas 2026-09-24 23:12:10 +02:00
commit 44009dc51d
2 changed files with 35 additions and 22 deletions

View file

@ -265,6 +265,16 @@ let
in
(j.merge or false) == true && j.directory == "/var/log/journal";
}
{
# The empty-directory trap this receiver used to fall into: `host` mode
# bind-mounts a host directory journald never actually writes into, so
# `merge`/`directory` above would keep validating and starting while
# the receiver reads nothing — silently, same as every other failure
# mode here. Guards against re-adding the exact flag this was fixed by
# dropping.
name = "the store's container does not link its journal onto the host";
ok = !(lib.elem "--link-journal=host" (baoWithCollector.containers.swarm-bao.extraFlags or [ ]));
}
{
# The whole journal, which is what the shared collector's unit allowlist
# is not. A `units` list here would render and deploy perfectly while