nix: run the forge on one host per swarm (deploy.forgejo.enable)
Every hive with hyperhive enabled ran its own hive-forge container, and its gateway answered forge.<swarm> with its own bridge IP, so on a multi-host swarm each hive talked to its own forge. deploy.forgejo.enable defaults to false and allSwarmServices sets it with mkDefault, like authelia and bao; singleHostSwarm gets it through that. The forge's OIDC client moves to a glue module gated on authelia, so a split authelia/forge swarm still registers it. CI now requires the forge on the same host, and the controller's forgeTokenFile defaults to null where the forge is not. Closes #4705 Refs #3782
This commit is contained in:
parent
21c17772b8
commit
978164dc53
15 changed files with 346 additions and 84 deletions
|
|
@ -82,8 +82,9 @@ in
|
|||
Run a Forgejo Actions runner in a `hive-ci` nixos-container.
|
||||
Grouped under `services.hyperhive.deploy.forgejo` because the runner
|
||||
is tightly coupled to the forge instance it registers against.
|
||||
Disabled by default; the internal forge it registers against is
|
||||
always present (mandatory), so enabling this is all that's needed.
|
||||
Disabled by default. It registers against the forge on this same
|
||||
host, so it requires
|
||||
{option}`services.hyperhive.deploy.forgejo.enable` here.
|
||||
|
||||
On first start the container auto-registers against hive-forge using
|
||||
hive-c0re's admin token — no manual token provisioning needed.
|
||||
|
|
@ -170,6 +171,20 @@ in
|
|||
Set behindGateway = true (it is the default).
|
||||
'';
|
||||
}
|
||||
{
|
||||
# The runner reaches the forge through THIS host's gateway, and
|
||||
# hive-c0re registers it through the local forge container; neither
|
||||
# exists on a host that does not run the forge. A runner on another
|
||||
# host, registered by the swarm instead, is a separate design.
|
||||
assertion = forgeDeployCfg.enable;
|
||||
message = ''
|
||||
services.hyperhive.deploy.forgejo.ci.enable requires
|
||||
services.hyperhive.deploy.forgejo.enable on the same host.
|
||||
The CI runner reaches the forge through this host's gateway and
|
||||
is registered through the local forge container, so it can only
|
||||
run where the forge does. Enable CI on the swarm's forge host.
|
||||
'';
|
||||
}
|
||||
];
|
||||
|
||||
# The runner's journal, named as the unit is *inside* the container —
|
||||
|
|
|
|||
Loading…
Reference in a new issue