nix: make swarm.authelia.url non-nullable, trim its docs
Review response on #4620: not having SSO is not a supported deployment, so the type should not permit it, and the docs paragraph explaining why SSO is always present is redundant once the type says so. - swarm.authelia.url drops types.nullOr. - Every consumer's null-arm is gone: two option defaults (swarm-controller's and swarm's own statusPublish.tokenEndpoint) that produced an empty/null placeholder when the URL was null now unconditionally compute the real derived URL. Five now-dead "assertion = ... != null" guards (swarm-authelia's bridge, swarm-grafana, swarm-otel, swarm-nats, hive-forge, hive-matrix) are removed as unreachable — in every case the same URL was already interpolated unconditionally a few lines below the guard. - grafanaNoSso, the module-eval fixture whose sole purpose was exercising the now-unsupported no-IdP refusal, is removed along with its dedicated test case; swarm.authelia.url = null is a type error now, not a value that reaches that assertion. - docs/swarm/services.md: cut the clause about setting the option to null and the sentence explaining why the URL is co-location- independent — both redundant now that the type enforces it.
This commit is contained in:
parent
4b6214305f
commit
5ec0ce90fd
10 changed files with 21 additions and 154 deletions
|
|
@ -69,13 +69,11 @@ provider, differentiated by roles and claims rather than by mechanism —
|
|||
there is one IdP and one auth path.
|
||||
|
||||
- **`deploy.authelia`** — run the container here.
|
||||
- **`swarm.authelia.url`** — where clients go to authenticate.
|
||||
Present on **every** hive and the same value on all of them:
|
||||
- **`swarm.authelia.url`** — where clients go to authenticate. Present
|
||||
on **every** hive and the same value on all of them:
|
||||
`https://<swarm.authelia.domain>`, whether or not this host runs the
|
||||
container. The name is what a client is given; resolution decides which
|
||||
address it reaches. Set it explicitly when joining a swarm whose IdP is
|
||||
under another name, or to `null` to say the swarm has no SSO — consumers
|
||||
then refuse rather than guessing an address.
|
||||
container. Set it explicitly when joining a swarm whose IdP is under
|
||||
another name.
|
||||
|
||||
swarm-controller writes the users database, not by hand: hive-c0re
|
||||
creates and destroys agents continuously, so the subject set is dynamic.
|
||||
|
|
|
|||
Loading…
Reference in a new issue