docs(#3255): record the controller's first persisted file
The crate's module doc claimed no persistence and no writes, which this change makes false, and docs/persistence.md had no swarm-controller entry at all — the webhook secret is the daemon's first persisted state.
This commit is contained in:
parent
b2596097d8
commit
645fd0d56c
2 changed files with 25 additions and 5 deletions
|
|
@ -468,6 +468,23 @@ sends to the swarm's snapshot store — see
|
||||||
[`docs/snapshot-store.md`](snapshot-store.md) for what a pushed
|
[`docs/snapshot-store.md`](snapshot-store.md) for what a pushed
|
||||||
snapshot contains and how the store authenticates a sender.
|
snapshot contains and how the store authenticates a sender.
|
||||||
|
|
||||||
|
## `/var/lib/swarm-controller/` (swarm-controller host only)
|
||||||
|
|
||||||
|
Only present on the one host running
|
||||||
|
`services.hyperhive.swarm.controller.enable`. systemd `StateDirectory=`,
|
||||||
|
so it survives restarts and redeploys.
|
||||||
|
|
||||||
|
- `webhook-secret` — the HMAC key the swarm's forge webhooks are signed
|
||||||
|
with. **Keep it.** It is handed to Forgejo when a hook is registered,
|
||||||
|
so replacing the file means every subsequent delivery fails
|
||||||
|
verification until the hook is re-registered with the new value. It is
|
||||||
|
generated automatically on first start; there is nothing to configure.
|
||||||
|
|
||||||
|
If the file is unreadable at startup the daemon still starts and logs
|
||||||
|
`webhook secret unavailable`; the webhook endpoint then answers 503
|
||||||
|
rather than accepting deliveries it cannot verify. Everything else the
|
||||||
|
controller serves is unaffected.
|
||||||
|
|
||||||
## Run-time dirs
|
## Run-time dirs
|
||||||
|
|
||||||
`/run/hyperhive/` is tmpfs-backed (systemd `RuntimeDirectory=`) but
|
`/run/hyperhive/` is tmpfs-backed (systemd `RuntimeDirectory=`) but
|
||||||
|
|
|
||||||
|
|
@ -3,11 +3,14 @@
|
||||||
//! `services.hyperhive.swarm.controller.enable` on, and serves HTTP over a
|
//! `services.hyperhive.swarm.controller.enable` on, and serves HTTP over a
|
||||||
//! unix socket that the hive-gateway's nginx proxies to.
|
//! unix socket that the hive-gateway's nginx proxies to.
|
||||||
//!
|
//!
|
||||||
//! Holds one piece of read-only state: the swarm's hive directory, loaded
|
//! Configuration is read-only and loaded once at startup from env vars the
|
||||||
//! once at startup from an env var the NixOS module sets
|
//! NixOS module sets (`services.hyperhive.swarm.controller`) — see
|
||||||
//! (`services.hyperhive.swarm.controller`) — see `load_hives`. Still no
|
//! `load_hives`. A config change means a redeploy, same as every other
|
||||||
//! persistence and no writes; a config change means a redeploy, same as
|
//! option this process reads.
|
||||||
//! every other option this process reads.
|
//!
|
||||||
|
//! The one thing it does persist is `webhook-secret` under its
|
||||||
|
//! `StateDirectory` (see `webhook`), because that key is handed to Forgejo
|
||||||
|
//! at registration and so cannot be regenerated per boot.
|
||||||
//!
|
//!
|
||||||
//! Distinct from `hive-c0re`, which is per-hive: c0re owns the agents on
|
//! Distinct from `hive-c0re`, which is per-hive: c0re owns the agents on
|
||||||
//! one host, this owns what is true across hives.
|
//! one host, this owns what is true across hives.
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue