nix: run the forge on one host per swarm (deploy.forgejo.enable)
Every hive with hyperhive enabled ran its own hive-forge container, and its gateway answered forge.<swarm> with its own bridge IP, so on a multi-host swarm each hive talked to its own forge. deploy.forgejo.enable defaults to false and allSwarmServices sets it with mkDefault, like authelia and bao; singleHostSwarm gets it through that. The forge's OIDC client moves to a glue module gated on authelia, so a split authelia/forge swarm still registers it. CI now requires the forge on the same host, and the controller's forgeTokenFile defaults to null where the forge is not. Closes #4705 Refs #3782
This commit is contained in:
parent
21c17772b8
commit
978164dc53
15 changed files with 346 additions and 84 deletions
|
|
@ -418,14 +418,33 @@ in
|
|||
)
|
||||
];
|
||||
|
||||
# ⚠️ `deploy.forgejo` is declared in ./hive-ci.nix, not here, and it is the
|
||||
# one entry with no `enable`: the forge is not optional — it is the canonical
|
||||
# store for the meta flake and every agent's config repo, so it deploys with
|
||||
# hyperhive itself. Running the CI runner is the only *deployment* decision
|
||||
# it has, which is exactly the `{ enable; ci; }` shape the header describes,
|
||||
# minus the half that does not apply. The knobs live with the module that
|
||||
# reads them; this file stays the registry of toggles.
|
||||
# ⚠️ Only `deploy.forgejo.enable` is declared here. The rest of
|
||||
# `deploy.forgejo` is in ./hive-forge/default.nix and ./hive-ci.nix: the
|
||||
# knobs live with the module that reads them; this file stays the registry
|
||||
# of toggles.
|
||||
options.services.hyperhive.deploy = {
|
||||
forgejo.enable = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
example = true;
|
||||
description = ''
|
||||
Run the swarm's forge in a `hive-forge` container on this host. A
|
||||
swarm has one forge, so one host turns this on. It is the
|
||||
canonical store for the meta flake and every agent's config repo,
|
||||
so the swarm needs it, but *this* host running it is a decision
|
||||
like any other shared service's.
|
||||
|
||||
With it off, this hive is a *client*: it reaches the swarm's
|
||||
forge at {option}`services.hyperhive.swarm.forge.domain`, which
|
||||
the operator's DNS must resolve to the forge's host. No container
|
||||
is created, and an existing one's state stays on disk under
|
||||
`/var/lib/nixos-containers/hive-forge/`.
|
||||
|
||||
{option}`services.hyperhive.deploy.allSwarmServices` turns it on,
|
||||
and `singleHostSwarm` through that.
|
||||
'';
|
||||
};
|
||||
|
||||
grafana.enable = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
|
|
|
|||
Loading…
Reference in a new issue