nix: run the forge on one host per swarm (deploy.forgejo.enable)
Every hive with hyperhive enabled ran its own hive-forge container, and its gateway answered forge.<swarm> with its own bridge IP, so on a multi-host swarm each hive talked to its own forge. deploy.forgejo.enable defaults to false and allSwarmServices sets it with mkDefault, like authelia and bao; singleHostSwarm gets it through that. The forge's OIDC client moves to a glue module gated on authelia, so a split authelia/forge swarm still registers it. CI now requires the forge on the same host, and the controller's forgeTokenFile defaults to null where the forge is not. Closes #4705 Refs #3782
This commit is contained in:
parent
21c17772b8
commit
978164dc53
15 changed files with 346 additions and 84 deletions
|
|
@ -4,10 +4,8 @@
|
|||
# where they live, and asserts the per-service `enable`s that follow —
|
||||
# the same mode-not-default shape as ./local-defaults.nix, one tier down.
|
||||
#
|
||||
# Only the *optional* services derive. The forge has no `enable` to
|
||||
# assert, because it is not optional — it is the canonical store for the
|
||||
# meta flake and every agent's config repo, so it deploys with hyperhive
|
||||
# itself.
|
||||
# The forge derives from here like the rest: every swarm needs one, but
|
||||
# only one host in it runs it.
|
||||
{
|
||||
lib,
|
||||
config,
|
||||
|
|
@ -23,20 +21,16 @@ in
|
|||
example = true;
|
||||
description = ''
|
||||
Host the swarm's shared services on this hive. The services that
|
||||
exist once per swarm rather than once per hive and are *optional*
|
||||
— the matrix homeserver, the SSO provider, the queue, the metrics
|
||||
and log stores — have their toggle asserted from this, so a
|
||||
swarm's service host is declared in one place.
|
||||
exist once per swarm rather than once per hive — the forge, the
|
||||
matrix homeserver, the SSO provider, the queue, the metrics and log
|
||||
stores — have their toggle asserted from this, so a swarm's service
|
||||
host is declared in one place.
|
||||
|
||||
Every toggle it asserts is a {option}`services.hyperhive.deploy.*`
|
||||
one, because "does THIS host run it" is a per-host decision — which
|
||||
is the same reason this option is a `deploy.*` one itself. See
|
||||
./deploy.nix.
|
||||
|
||||
The forge is swarm-wide too but has nothing to assert: it is the
|
||||
canonical store for the meta flake and every agent's config repo,
|
||||
so it deploys with hyperhive itself and is not optional.
|
||||
|
||||
`services.hyperhive.deploy.singleHostSwarm` turns this on as part
|
||||
of the all-on-one-box mode. Set it directly to run the swarm's
|
||||
services on a host that is not otherwise all-local — a dedicated
|
||||
|
|
@ -105,4 +99,10 @@ in
|
|||
# placeable on a host of its own — it can be set directly here and
|
||||
# turned off wherever this switch happens to be on.
|
||||
config.services.hyperhive.deploy.bao.enable = lib.mkDefault deployCfg.allSwarmServices;
|
||||
|
||||
# The forge. Every swarm needs it, but one host runs it: a hive that does
|
||||
# not is a *client*, reaching it at `swarm.forge.domain`. Without this a
|
||||
# `singleHostSwarm` box, which gets here through `allSwarmServices`, would
|
||||
# have no forge at all.
|
||||
config.services.hyperhive.deploy.forgejo.enable = lib.mkDefault deployCfg.allSwarmServices;
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in a new issue