containers: put journal files on the host, where the collector looks
The swarm collector reads /var/log/journal and has never seen a single container unit. mara's count-by-unit against VictoriaLogs returns four units, all host-tier; openbao -- which runs inside the swarm-bao container -- is absent. Cause: nixos-containers.nix hardcodes `--link-journal=try-guest` for every non-ephemeral container. With `guest`, the host's /var/log/journal/<machine-id> is a SYMLINK into the container's transient root; a reader in the host namespace cannot follow it, and it dangles as soon as the container stops. `ls -la /var/log/journal/` on the host shows one real directory and a pile of `-> /tmp/nspawn-root-*` links dating back to May. swarm-otel.nix asserted the opposite, and that assertion is why the receiver's path was considered sufficient: it said the files "live here" and are "bind-mounted into the guest rather than the other way round". That describes `--link-journal=host`. The same sentence names the flag we actually use. The flag was right and the behaviour it described was not, so grepping for the flag confirmed the comment and taught nothing. `containers.<name>.extraFlags` feeds EXTRA_NSPAWN_FLAGS, which the invocation expands after the hardcoded flag, so `--link-journal=host` wins. The comment now describes what the code does instead of the other way round. Two payoffs, and the smaller one is the one the issue is about: container logs become collectable, and -- independently -- they become durable at all, rather than dying with the container. Ten identical edits because ten host-modules hand-roll their own container block; that duplication is #3773, not something to invent an abstraction for here. NOT VERIFIED: that systemd-nspawn honours the last `--link-journal` of two. Everything else here is read out of nixpkgs; that step is a claim about its argument parsing which cannot be exercised without starting a container. It is settled by deploying one and re-running the `ls`: the machine-id entry becomes a real directory instead of a symlink. Refs #3849
This commit is contained in:
parent
cdac6091eb
commit
9c601c4166
10 changed files with 42 additions and 6 deletions
|
|
@ -634,6 +634,9 @@ in
|
|||
containers.hive-forge = {
|
||||
autoStart = true;
|
||||
ephemeral = false;
|
||||
# Journal files on the host, not inside the container: nixpkgs hardcodes
|
||||
# --link-journal=try-guest, and EXTRA_NSPAWN_FLAGS expands after it.
|
||||
extraFlags = [ "--link-journal=host" ];
|
||||
# Share host netns — forgejo's HTTP / SSH listeners then look
|
||||
# exactly like a host-side service, no port forwarding dance,
|
||||
# and agent containers (which also share host netns) reach it
|
||||
|
|
|
|||
Loading…
Reference in a new issue