deploy: move authelia's three host paths out of swarm.authelia
`usersFile`, `hostClientSecretDir` and `hostUsersFile` are filesystem paths that only exist on the machine running the `swarm-authelia` container. A hive that does not run it has nothing at any of them, so they fail the swarm-wide test the namespace's header states. `usersFile` is a path *inside* the container and still belongs on the deploy side: a path's scope is the scope of the filesystem it names, and that filesystem is this host's container root. The two `host*` options are `readOnly` and derived, so nothing can set them through the rename shims — those serve readers. The shims are still required: `mkRenamedOptionModule` is what keeps an out-of-tree module reading the old path resolving at all. Seven reads went through an alias rather than a full path (`autheliaCfg.hostClientSecretDir` in five modules, `.hostUsersFile` in a sixth, `swarmCfg.authelia.hostClientSecretDir` in a seventh). Every one of those files already binds `deployCfg`, so the repoint needed no new alias. Four more sites were prose, including one in `docs/`, which no grep restricted to `nix/` would have found.
This commit is contained in:
parent
9d55cba786
commit
9c09653603
12 changed files with 102 additions and 74 deletions
|
|
@ -234,11 +234,11 @@ in
|
|||
if
|
||||
config.services.hyperhive.deploy.authelia.enable && config.services.hyperhive.hiveName != null
|
||||
then
|
||||
"${config.services.hyperhive.swarm.authelia.hostClientSecretDir}/"
|
||||
"${config.services.hyperhive.deploy.authelia.hostClientSecretDir}/"
|
||||
+ "${config.services.hyperhive.swarm.authelia.hiveClientPrefix}${config.services.hyperhive.hiveName}.secret"
|
||||
else
|
||||
null;
|
||||
defaultText = lib.literalExpression ''"''${swarm.authelia.hostClientSecretDir}/''${swarm.authelia.hiveClientPrefix}''${hiveName}.secret" when this host runs the swarm's IdP, else null'';
|
||||
defaultText = lib.literalExpression ''"''${deploy.authelia.hostClientSecretDir}/''${swarm.authelia.hiveClientPrefix}''${hiveName}.secret" when this host runs the swarm's IdP, else null'';
|
||||
example = "/var/lib/secrets/hive-telemetry.secret";
|
||||
description = ''
|
||||
Absolute path to this hive's OAuth2 client secret, used to
|
||||
|
|
|
|||
Loading…
Reference in a new issue