nix: run the forge on one host per swarm (deploy.forgejo.enable)

Every hive with hyperhive enabled ran its own hive-forge container, and
its gateway answered forge.<swarm> with its own bridge IP, so on a
multi-host swarm each hive talked to its own forge.

deploy.forgejo.enable defaults to false and allSwarmServices sets it with
mkDefault, like authelia and bao; singleHostSwarm gets it through that.
The forge's OIDC client moves to a glue module gated on authelia, so a
split authelia/forge swarm still registers it. CI now requires the forge
on the same host, and the controller's forgeTokenFile defaults to null
where the forge is not.

Closes #4705
Refs #3782
This commit is contained in:
atlas 2026-09-24 19:44:04 +02:00 • committed by mara
commit 978164dc53
15 changed files with 346 additions and 84 deletions

View file

@ -4,10 +4,8 @@
# where they live, and asserts the per-service `enable`s that follow —
# the same mode-not-default shape as ./local-defaults.nix, one tier down.
#
# Only the *optional* services derive. The forge has no `enable` to
# assert, because it is not optional — it is the canonical store for the
# meta flake and every agent's config repo, so it deploys with hyperhive
# itself.
# The forge derives from here like the rest: every swarm needs one, but
# only one host in it runs it.
{
lib,
config,
@ -23,20 +21,16 @@ in
example = true;
description = ''
Host the swarm's shared services on this hive. The services that
exist once per swarm rather than once per hive and are *optional*
— the matrix homeserver, the SSO provider, the queue, the metrics
and log stores — have their toggle asserted from this, so a
swarm's service host is declared in one place.
exist once per swarm rather than once per hive — the forge, the
matrix homeserver, the SSO provider, the queue, the metrics and log
stores — have their toggle asserted from this, so a swarm's service
host is declared in one place.
Every toggle it asserts is a {option}`services.hyperhive.deploy.*`
one, because "does THIS host run it" is a per-host decision — which
is the same reason this option is a `deploy.*` one itself. See
./deploy.nix.
The forge is swarm-wide too but has nothing to assert: it is the
canonical store for the meta flake and every agent's config repo,
so it deploys with hyperhive itself and is not optional.
`services.hyperhive.deploy.singleHostSwarm` turns this on as part
of the all-on-one-box mode. Set it directly to run the swarm's
services on a host that is not otherwise all-local — a dedicated
@ -105,4 +99,10 @@ in
# placeable on a host of its own — it can be set directly here and
# turned off wherever this switch happens to be on.
config.services.hyperhive.deploy.bao.enable = lib.mkDefault deployCfg.allSwarmServices;
# The forge. Every swarm needs it, but one host runs it: a hive that does
# not is a *client*, reaching it at `swarm.forge.domain`. Without this a
# `singleHostSwarm` box, which gets here through `allSwarmServices`, would
# have no forge at all.
config.services.hyperhive.deploy.forgejo.enable = lib.mkDefault deployCfg.allSwarmServices;
}