swarm: default every queue URL to the queue's name on every hive
A remote hive dialled nothing until an operator copied the queue's URL into it, though the URL is the same string everywhere. statusPublish.natsUrl, queue.agentNatsUrl and controller.queue.natsUrl now default to tls://<swarm.nats.domain>:<port> unconditionally. The statusPublish assertion treated a URL without a secret as a half config. With the URL a default on every hive, only the secret claims publishing: the assertion now refuses a secret without a URL or token endpoint, and hive-c0re's status environment is gated on the secret too, so a hive without one publishes nothing instead of reading a missing credential.
This commit is contained in:
parent
0081d75c86
commit
a5259146dc
8 changed files with 220 additions and 129 deletions
|
|
@ -338,10 +338,8 @@ nothing has to re-publish.
|
|||
|
||||
### Making a hive report
|
||||
|
||||
Three options, on the **hive**, set together or not at all — a
|
||||
half-configured hive is an eval error rather than one that quietly never
|
||||
reports. They sit in two namespaces, because two of them are facts about
|
||||
_this machine_ and one is the swarm's single address:
|
||||
Three options on the **hive**. They sit in two namespaces, because two of them
|
||||
are facts about _this machine_ and one is the swarm's single address:
|
||||
|
||||
| option | what to set it to |
|
||||
| ------------------------------------------------------- | --------------------------------------------- |
|
||||
|
|
@ -349,10 +347,14 @@ _this machine_ and one is the swarm's single address:
|
|||
| `swarm.statusPublish.tokenEndpoint` | the swarm IdP's `/api/oidc/token` |
|
||||
| `deploy.hive-controller.statusPublish.clientSecretFile` | path to this hive's client secret, plaintext |
|
||||
|
||||
On a host that runs the queue and the IdP itself, all three default to
|
||||
the local ones and there is nothing to set. Any other hive needs them
|
||||
spelled out, and needs the secret to physically be there: the swarm does
|
||||
not distribute it. Copy `hive-<hiveName>.secret` out of the swarm host's
|
||||
The queue URL and the token endpoint default to the swarm's own addresses on
|
||||
every hive, so there is nothing to set for them. The secret is what turns
|
||||
publishing on: a hive without it doesn't publish. A secret without the other
|
||||
two is an eval error rather than a hive that quietly never reports.
|
||||
|
||||
On a host that runs the queue and the IdP, the secret defaults to the local one.
|
||||
Any other hive needs the secret to physically be there, because the swarm
|
||||
doesn't distribute it. Copy `hive-<hiveName>.secret` out of the swarm host's
|
||||
`deploy.authelia.hostClientSecretDir` with whatever secret management the
|
||||
deployment already uses.
|
||||
|
||||
|
|
@ -390,11 +392,12 @@ with the credential itself and aren't configurable.
|
|||
| `deploy.hive-controller.queue.agentNatsUrl` | where the queue listens, as an agent **container** reaches it |
|
||||
| `swarm.statusPublish.tokenEndpoint` | the swarm IdP's `/api/oidc/token` — the same one the hive uses |
|
||||
|
||||
On a host that runs the queue, `agentNatsUrl` defaults to the same
|
||||
`tls://<swarm.nats.domain>:<swarm.nats.port>` as the hive's own. Inside a
|
||||
container the name resolves to the bridge address, where the firewall opens the
|
||||
port. ⚠️ **Never a loopback address here**: an agent has its own network
|
||||
namespace, so `127.0.0.1` reaches the agent.
|
||||
On every hive, `agentNatsUrl` defaults to the same
|
||||
`tls://<swarm.nats.domain>:<swarm.nats.port>` as the hive's own. On the queue's
|
||||
host the name resolves inside a container to the bridge address, where the
|
||||
firewall opens the port; on any other hive it resolves through the host's DNS,
|
||||
like the store's name. ⚠️ **Never a loopback address here**: an agent has its
|
||||
own network namespace, so `127.0.0.1` reaches the agent.
|
||||
|
||||
The harness sees four variables, and treats them as all-or-none:
|
||||
`HIVE_AGENT_NATS_URL` and `HIVE_AGENT_OIDC_TOKEN_ENDPOINT` from the two options
|
||||
|
|
|
|||
Loading…
Reference in a new issue