Watch
0
0
Fork
You've already forked hyperhive
0

swarm-ui: build authelia/grafana/metrics/logs links from swarm domains

The swarm-controller module builds the Authelia, Grafana, Metrics and
Logs quick links from services.hyperhive.swarm.<service>.domain, on the
controller's host, instead of each service module adding its entry only
on the host that runs it. A controller whose swarm runs those services
on other hosts lists them in its /api/links popover.

Forge, matrix and bao links are not moved yet: forge waits on #4891,
matrix and bao on whether their GUI gate becomes swarm-level.

Refs #4885
This commit is contained in:
atlas 2026-10-02 17:53:07 +02:00
commit 8628e0ecdd
7 changed files with 108 additions and 57 deletions

View file

@ -18,6 +18,40 @@ let
deployCfg = config.services.hyperhive.deploy;
autheliaCfg = config.services.hyperhive.swarm.authelia;
natsCfg = config.services.hyperhive.swarm.nats;
swarmCfg = config.services.hyperhive.swarm;
# Quick links to swarm services, built from `swarm.*` options alone: every
# host evaluates the same entries, whichever host runs each service. One
# entry per service; reading a `deploy.*` option here would tie a link to
# where its service runs.
swarmServiceLinks =
map
(s: {
inherit (s) label icon;
url = "https://${s.domain}/";
})
[
{
label = "Authelia";
icon = "🔑";
inherit (swarmCfg.authelia) domain;
}
{
label = "Grafana";
icon = "📊";
inherit (swarmCfg.grafana) domain;
}
{
label = "Metrics";
icon = "📈";
inherit (swarmCfg.victoriametrics) domain;
}
{
label = "Logs";
icon = "📜";
inherit (swarmCfg.victorialogs) domain;
}
];
# Where the secret store is, and whether this host holds the controller's
# own leaf for it. ⚠️ The controller's pair, NOT `deploy.bao.clientCertFile`
@ -411,21 +445,18 @@ in
links menu (`GET /api/links`). Same shape and same
zero-code-change-to-extend idea as `hyperhive.dashboardLinks`
(`nix/agent-modules/dashboard-links.nix`), one level up: rather
than one central hardcoded list, each service's own module
contributes its own entry when it is actually enabled on this
host — `swarm-authelia.nix`, `hive-matrix.nix` and
`hive-forge/default.nix` all do — the same list-merge idiom
`services.hyperhive.gateway.localNames` already uses. A future
service module can push its own entry the same way, and an
operator can add arbitrary extra entries here directly; neither
needs a swarm-controller or swarm-ui change.
than one fixed list, definitions merge with the list-merge idiom
`services.hyperhive.gateway.localNames` uses, so an operator can
add arbitrary extra entries here directly with no swarm-controller
or swarm-ui change.
Only meaningful on the host that actually runs the controller —
entries contributed on any other host are computed but never
read. In a swarm that splits `swarm-authelia`/`hive-matrix`/
`hive-forge` across hosts other than the controller's, this list
only reflects what is enabled locally; see each contributing
module's own activation condition.
The Authelia, Grafana, Metrics and Logs entries come from
`services.hyperhive.swarm.<service>.domain`, so they are present
whichever host runs each service. `hive-matrix.nix`,
`hive-forge/default.nix` and `swarm-ui.nix` contribute their own
entries, and only where they are enabled on this host.
Read only on the host that runs the controller.
'';
};
@ -643,6 +674,8 @@ in
};
config = lib.mkIf deployCfg.swarm-controller.enable {
services.hyperhive.swarm.controller.links = swarmServiceLinks;
users.users.swarm-controller = {
isSystemUser = true;
group = "swarm-controller";