nix: run the forge on one host per swarm (deploy.forgejo.enable)
Every hive with hyperhive enabled ran its own hive-forge container, and its gateway answered forge.<swarm> with its own bridge IP, so on a multi-host swarm each hive talked to its own forge. deploy.forgejo.enable defaults to false and allSwarmServices sets it with mkDefault, like authelia and bao; singleHostSwarm gets it through that. The forge's OIDC client moves to a glue module gated on authelia, so a split authelia/forge swarm still registers it. CI now requires the forge on the same host, and the controller's forgeTokenFile defaults to null where the forge is not. Closes #4705 Refs #3782
This commit is contained in:
parent
21c17772b8
commit
978164dc53
15 changed files with 346 additions and 84 deletions
|
|
@ -10,8 +10,7 @@ services.hyperhive.deploy.allSwarmServices = true;
|
|||
```
|
||||
|
||||
**`deploy.allSwarmServices` is what "the swarm's shared services run
|
||||
here" means: every once-per-swarm service that's _optional_ takes its
|
||||
`enable` from it.** That's the whole rule, stated once — the per-service
|
||||
here" means: every once-per-swarm service takes its `enable` from it.** That's the whole rule, stated once — the per-service
|
||||
sections below don't repeat it, so a service that stops deriving is a
|
||||
visible difference rather than one more paragraph saying the same thing.
|
||||
|
||||
|
|
@ -26,10 +25,24 @@ operator saying so rather than something inferred. With them off, a hive
|
|||
is a _client_ of those services — it configures how to reach them and
|
||||
runs none of them.
|
||||
|
||||
The forge is the exception, and not because it's per-hive: it's
|
||||
swarm-wide but **not optional**, being the canonical store for the meta
|
||||
flake and every agent's config repo, so it deploys with hyperhive itself
|
||||
and has no `enable` to derive from anything.
|
||||
That includes the forge (`deploy.forgejo.enable`). Every swarm needs
|
||||
one, being the canonical store for the meta flake and every agent's
|
||||
config repo, so **exactly one host must turn it on**: `singleHostSwarm`,
|
||||
`allSwarmServices`, or `deploy.forgejo.enable = true` set by hand. A
|
||||
host that enables its services one by one without any of those runs no
|
||||
forge.
|
||||
|
||||
A hive that runs none of these reaches each one by name — the forge at
|
||||
`forge.<swarm-domain>`, for example. Only the host running a service
|
||||
answers its name from its own resolver, so on a swarm spread over
|
||||
more than one host, the operator's DNS has to resolve those names to that
|
||||
host.
|
||||
|
||||
A hive that stops running the forge keeps the old container's state at
|
||||
`/var/lib/nixos-containers/hive-forge/`. Nothing moves it to the swarm's
|
||||
forge: push anything worth keeping there by hand. Its
|
||||
`/var/lib/hyperhive/forge-core-token` came from that old forge and
|
||||
fails against the swarm's one.
|
||||
|
||||
## Deployment shapes
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue