Watch
0
0
Fork
You've already forked hyperhive
0

nix: require swarm.domain on every host

Swarm options are the same on all hosts, so the swarm.domain assertion is no longer gated on deploy.hive-controller.enable.

Refs #4872
This commit is contained in:
atlas 2026-10-02 08:12:46 +02:00 • committed by mara
commit 82463388c5
2 changed files with 19 additions and 12 deletions

View file

@ -184,21 +184,28 @@ in
backstop.
'';
}
];
})
# Un-gated: the swarm's options are identical on every host, so a host
# running no hive and no swarm service needs the value too. The
# `.invalid` fallbacks described above keep this message reachable.
{
assertions = [
{
assertion = config.services.hyperhive.swarm.domain != null;
message = ''
hyperhive requires services.hyperhive.swarm.domain to be
set — the DNS domain of the swarm this hive belongs to,
of which this hive occupies one sub-domain. There is no
fallback: a guessed value would be a wrong hostname that
evaluates cleanly and deploys. Set it
(`services.hyperhive.swarm.domain = "example.com";`) —
with `hiveName` it also derives
`services.hyperhive.domain` for you.
hyperhive requires services.hyperhive.swarm.domain to be set
on every host, to the same value on every host of the swarm —
the DNS domain of the swarm, of which each hive occupies one
sub-domain. There is no fallback: a guessed value would be a
wrong hostname that evaluates cleanly and deploys. Set it
(`services.hyperhive.swarm.domain = "example.com";`) — with
`hiveName` it also derives `services.hyperhive.domain` for you.
'';
}
];
})
}
# The bridge itself, up only where something hangs off it. Private
# netns is still the only container mode.

View file

@ -117,9 +117,9 @@ in
`services.hyperhive.hiveName`, list the hives by name, and no
hive in the swarm states an address at all.
**Required** when
`services.hyperhive.deploy.hive-controller.enable`, and deliberately
not defaulted: there is no fallback worth having. A guessed
**Required** on every host that imports this module, with the
same value on every host of the swarm, and deliberately not
defaulted: there is no fallback worth having. A guessed
swarm domain is a wrong hostname that evaluates cleanly and
deploys, which is worse than an eval failure telling an
operator to write down the one address their swarm answers to.