swarm: default every queue URL to the queue's name on every hive
A remote hive dialled nothing until an operator copied the queue's URL into it, though the URL is the same string everywhere. statusPublish.natsUrl, queue.agentNatsUrl and controller.queue.natsUrl now default to tls://<swarm.nats.domain>:<port> unconditionally. The statusPublish assertion treated a URL without a secret as a half config. With the URL a default on every hive, only the secret claims publishing: the assertion now refuses a secret without a URL or token endpoint, and hive-c0re's status environment is gated on the secret too, so a hive without one publishes nothing instead of reading a missing credential.
This commit is contained in:
parent
0081d75c86
commit
a5259146dc
8 changed files with 220 additions and 129 deletions
|
|
@ -133,12 +133,12 @@ in
|
|||
./options.nix
|
||||
./theme.nix
|
||||
# Hive-CA trust for this daemon's outbound TLS. Nothing it is given by
|
||||
# default is https — the forge, matrix and queue URLs all resolve to
|
||||
# plain http or loopback — so this changes nothing on an all-local
|
||||
# hive. It matters for the split-host shape the options invite:
|
||||
# `swarm.matrix.apiUrl`'s own example is `https://matrix.example.com`,
|
||||
# and pointing it (or `deploy.hive-controller.statusPublish.natsUrl`)
|
||||
# at another hive's
|
||||
# default is https — the forge and matrix URLs resolve to plain http or
|
||||
# loopback, and the queue's TLS is verified against
|
||||
# `HIVE_C0RE_OIDC_CA_FILE` (../hive-tls.nix), not this bundle — so this
|
||||
# changes nothing on an all-local hive. It matters for the split-host
|
||||
# shape the options invite: `swarm.matrix.apiUrl`'s own example is
|
||||
# `https://matrix.example.com`, and pointing it at another hive's
|
||||
# gateway means verifying a leaf signed by a CA generated at runtime,
|
||||
# which no build-time trust store can contain.
|
||||
#
|
||||
|
|
|
|||
Loading…
Reference in a new issue