swarm-otel: ship the whole host journal, drop user sessions after it
The swarm collector's journald receiver read only the units listed in `services.hyperhive.swarm.otel.journaldUnits`. A unit nobody listed never reached the store, and a misspelt entry shipped nothing without an error. The list existed to keep an operator's desktop session out of a store every swarm operator can read, but the receiver can only match positively, so the only way to express "not user sessions" was to name every service instead. The receiver now reads the whole host journal, and a new `filter/exclude-user-sessions` processor in the `logs/<swarm>` pipeline drops records whose `_SYSTEMD_SLICE` is `user-<uid>.slice` (session scopes and `user@<uid>.service`). The per-hive `logs/<hive>` pipelines carry agent-container journals only and get no filter. `journaldUnits` is removed with `mkRemovedOptionModule`, together with its non-empty assertion and the entry each host module added. The four module-eval membership checks go with it, replaced by one structural case in swarm-otel-core. Closes #3646
This commit is contained in:
parent
710f5b7b8c
commit
6b1e825c0a
25 changed files with 72 additions and 324 deletions
|
|
@ -126,17 +126,6 @@ in
|
|||
# file's `let` and are not option surface.
|
||||
services.hyperhive.gateway.lib = vhostLib;
|
||||
|
||||
# Every request to every hyperhive service passes through here, so this
|
||||
# is the one unit that can say a service was unreachable rather than
|
||||
# merely quiet. Named even on hives that run no swarm collector: the
|
||||
# option is inert unless one is collecting on this host. nginx
|
||||
# `Requires=` the self-signed copy, so its journal is the other half of
|
||||
# why nginx did not start.
|
||||
services.hyperhive.swarm.otel.journaldUnits = [
|
||||
"nginx"
|
||||
]
|
||||
++ lib.optional useSelfSigned "hive-gateway-self-signed-cert";
|
||||
|
||||
assertions = [
|
||||
{
|
||||
assertion = !(cfg.tls.acme.enable && cfg.tls.certDir != null);
|
||||
|
|
|
|||
|
|
@ -30,10 +30,6 @@ in
|
|||
# address, so the resolver is itself a consumer one layer down.
|
||||
services.hyperhive.network.enable = lib.mkDefault true;
|
||||
|
||||
# A name that stops resolving presents as every client timing out at
|
||||
# once, so this unit's journal is worth reading swarm-wide.
|
||||
services.hyperhive.swarm.otel.journaldUnits = [ "dnsmasq" ];
|
||||
|
||||
# The host asks the hive's own resolver, at the BRIDGE IP.
|
||||
#
|
||||
# Every container inherits a COPY of this host's `/etc/resolv.conf`
|
||||
|
|
|
|||
Loading…
Reference in a new issue