Watch
0
0
Fork
You've already forked hyperhive
0

nix: run the forge on one host per swarm (deploy.forgejo.enable)

Every hive with hyperhive enabled ran its own hive-forge container, and
its gateway answered forge.<swarm> with its own bridge IP, so on a
multi-host swarm each hive talked to its own forge.

deploy.forgejo.enable defaults to false and allSwarmServices sets it with
mkDefault, like authelia and bao; singleHostSwarm gets it through that.
The forge's OIDC client moves to a glue module gated on authelia, so a
split authelia/forge swarm still registers it. CI now requires the forge
on the same host, and the controller's forgeTokenFile defaults to null
where the forge is not.

Closes #4705
Refs #3782
This commit is contained in:
atlas 2026-09-24 19:44:04 +02:00 • committed by mara
commit 978164dc53
15 changed files with 346 additions and 84 deletions

View file

@ -418,14 +418,33 @@ in
)
];
# ⚠️ `deploy.forgejo` is declared in ./hive-ci.nix, not here, and it is the
# one entry with no `enable`: the forge is not optional — it is the canonical
# store for the meta flake and every agent's config repo, so it deploys with
# hyperhive itself. Running the CI runner is the only *deployment* decision
# it has, which is exactly the `{ enable; ci; }` shape the header describes,
# minus the half that does not apply. The knobs live with the module that
# reads them; this file stays the registry of toggles.
# ⚠️ Only `deploy.forgejo.enable` is declared here. The rest of
# `deploy.forgejo` is in ./hive-forge/default.nix and ./hive-ci.nix: the
# knobs live with the module that reads them; this file stays the registry
# of toggles.
options.services.hyperhive.deploy = {
forgejo.enable = lib.mkOption {
type = lib.types.bool;
default = false;
example = true;
description = ''
Run the swarm's forge in a `hive-forge` container on this host. A
swarm has one forge, so one host turns this on. It is the
canonical store for the meta flake and every agent's config repo,
so the swarm needs it, but *this* host running it is a decision
like any other shared service's.
With it off, this hive is a *client*: it reaches the swarm's
forge at {option}`services.hyperhive.swarm.forge.domain`, which
the operator's DNS must resolve to the forge's host. No container
is created, and an existing one's state stays on disk under
`/var/lib/nixos-containers/hive-forge/`.
{option}`services.hyperhive.deploy.allSwarmServices` turns it on,
and `singleHostSwarm` through that.
'';
};
grafana.enable = lib.mkOption {
type = lib.types.bool;
default = false;