deploy: move the forge CI runner toggle out of swarm
Last of the swarm.* -> deploy.* moves for the enable-shaped options. Whether this host also runs the CI runner is a per-machine decision, so it was sitting in the namespace that has to be identical swarm-wide. Renames all five options, not just enable: name, concurrency, labels and package all describe the runner THIS host would run, and leaving them behind would keep the original defect for four more options. One rename entry each, because ci is a plain attrset rather than a submodule type, so there is no parent path to rename in one go. deploy.forgejo is the name deploy.nix's own header already specifies, including this exact case -- "ci (does this host run the runner too) is exactly that shape". It is the only entry with no enable: the forge is not optional, it deploys with hyperhive itself, so running the runner is the only deployment decision it has. Also fixes hive-c0re/src/forge/ci_runner.rs, whose doc comment named services.hyperhive.forge.ci.enable -- missing the swarm. segment, so it had never resolved to a real option.
This commit is contained in:
parent
33fafc8c19
commit
4423da4899
6 changed files with 47 additions and 12 deletions
|
|
@ -69,8 +69,43 @@ in
|
|||
[ "services" "hyperhive" "swarm" "otel" "enable" ]
|
||||
[ "services" "hyperhive" "deploy" "swarm-otel" "enable" ]
|
||||
)
|
||||
|
||||
# The CI runner, and the only entry here that renames more than an
|
||||
# `enable`: every knob under it describes the runner THIS host would run,
|
||||
# so leaving `name`/`concurrency`/`labels`/`package` in the namespace that
|
||||
# must be identical swarm-wide would keep the original defect for four
|
||||
# more options. Renamed one by one because `ci` is a plain attrset of
|
||||
# options rather than a submodule type, so there is no parent path to
|
||||
# rename in a single entry.
|
||||
(lib.mkRenamedOptionModule
|
||||
[ "services" "hyperhive" "swarm" "forge" "ci" "enable" ]
|
||||
[ "services" "hyperhive" "deploy" "forgejo" "ci" "enable" ]
|
||||
)
|
||||
(lib.mkRenamedOptionModule
|
||||
[ "services" "hyperhive" "swarm" "forge" "ci" "name" ]
|
||||
[ "services" "hyperhive" "deploy" "forgejo" "ci" "name" ]
|
||||
)
|
||||
(lib.mkRenamedOptionModule
|
||||
[ "services" "hyperhive" "swarm" "forge" "ci" "concurrency" ]
|
||||
[ "services" "hyperhive" "deploy" "forgejo" "ci" "concurrency" ]
|
||||
)
|
||||
(lib.mkRenamedOptionModule
|
||||
[ "services" "hyperhive" "swarm" "forge" "ci" "labels" ]
|
||||
[ "services" "hyperhive" "deploy" "forgejo" "ci" "labels" ]
|
||||
)
|
||||
(lib.mkRenamedOptionModule
|
||||
[ "services" "hyperhive" "swarm" "forge" "ci" "package" ]
|
||||
[ "services" "hyperhive" "deploy" "forgejo" "ci" "package" ]
|
||||
)
|
||||
];
|
||||
|
||||
# ⚠️ `deploy.forgejo` is declared in ./hive-ci.nix, not here, and it is the
|
||||
# one entry with no `enable`: the forge is not optional — it is the canonical
|
||||
# store for the meta flake and every agent's config repo, so it deploys with
|
||||
# hyperhive itself. Running the CI runner is the only *deployment* decision
|
||||
# it has, which is exactly the `{ enable; ci; }` shape the header describes,
|
||||
# minus the half that does not apply. The knobs live with the module that
|
||||
# reads them; this file stays the registry of toggles.
|
||||
options.services.hyperhive.deploy = {
|
||||
grafana.enable = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
|
|
|
|||
|
|
@ -5,7 +5,7 @@
|
|||
...
|
||||
}:
|
||||
let
|
||||
cfg = config.services.hyperhive.swarm.forge.ci;
|
||||
cfg = config.services.hyperhive.deploy.forgejo.ci;
|
||||
forgeCfg = config.services.hyperhive.swarm.forge;
|
||||
gatewayCfg = config.services.hyperhive.gateway;
|
||||
networkCfg = config.services.hyperhive.network;
|
||||
|
|
@ -76,7 +76,7 @@ in
|
|||
# nspawn containers can't create the user-namespaces that nix sandboxing
|
||||
# requires. See docs/gotchas.md.
|
||||
|
||||
options.services.hyperhive.swarm.forge.ci = {
|
||||
options.services.hyperhive.deploy.forgejo.ci = {
|
||||
enable = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
|
|
@ -166,7 +166,7 @@ in
|
|||
{
|
||||
assertion = forgeCfg.behindGateway;
|
||||
message = ''
|
||||
services.hyperhive.swarm.forge.ci.enable requires
|
||||
services.hyperhive.deploy.forgejo.ci.enable requires
|
||||
services.hyperhive.swarm.forge.behindGateway = true.
|
||||
The CI container runs with a private network namespace and
|
||||
reaches the forge through the gateway vhost on the bridge IP.
|
||||
|
|
|
|||
|
|
@ -88,7 +88,7 @@ let
|
|||
# blip otherwise reds every `actions/checkout@vN` fetch from
|
||||
# data.forgejo.org). Auto-append a pull-mirror of it and point
|
||||
# forgejo's DEFAULT_ACTIONS_URL at this instance so `uses:` resolves local.
|
||||
ciEnabled = config.services.hyperhive.swarm.forge.ci.enable;
|
||||
ciEnabled = config.services.hyperhive.deploy.forgejo.ci.enable;
|
||||
actionCheckoutMirror = {
|
||||
upstream = "https://github.com/actions/checkout";
|
||||
dest = "actions/checkout";
|
||||
|
|
@ -350,7 +350,7 @@ in
|
|||
so a host-resolver blip leaves a *stale* mirror, never a hard
|
||||
failure on whatever reads it.
|
||||
|
||||
When `services.hyperhive.swarm.forge.ci.enable` is set, an
|
||||
When `services.hyperhive.deploy.forgejo.ci.enable` is set, an
|
||||
`actions/checkout` mirror is auto-appended to this list and
|
||||
forgejo's `DEFAULT_ACTIONS_URL` is pointed at this instance, so CI
|
||||
`uses: actions/checkout@vN` steps resolve entirely on loopback with
|
||||
|
|
|
|||
Loading…
Reference in a new issue