swarm: default every queue URL to the queue's name on every hive
A remote hive dialled nothing until an operator copied the queue's URL into it, though the URL is the same string everywhere. statusPublish.natsUrl, queue.agentNatsUrl and controller.queue.natsUrl now default to tls://<swarm.nats.domain>:<port> unconditionally. The statusPublish assertion treated a URL without a secret as a half config. With the URL a default on every hive, only the secret claims publishing: the assertion now refuses a secret without a URL or token endpoint, and hive-c0re's status environment is gated on the secret too, so a hive without one publishes nothing instead of reading a missing credential.
This commit is contained in:
parent
0081d75c86
commit
a5259146dc
8 changed files with 220 additions and 129 deletions
|
|
@ -86,31 +86,13 @@ in
|
|||
config.services.hyperhive.deploy.nats.autoGenerateCallout =
|
||||
lib.mkDefault cfg.deploy.singleHostSwarm;
|
||||
|
||||
# ⚠️ Every `swarm.*` default this mode sets lives INSIDE this attrset, not
|
||||
# as a second `config.services.hyperhive.swarm.…` path beside it — written
|
||||
# that way the two definitions of `swarm` collide and the nested one is
|
||||
# silently lost. The gate caught exactly that on the controller's queue URL,
|
||||
# when this mode still set it: mode on, `natsUrl` still "".
|
||||
config.services.hyperhive.swarm = {
|
||||
ca.autoConfigure = lib.mkDefault cfg.deploy.singleHostSwarm;
|
||||
# The controller's queue coordinates. Kept with the mode, not in the
|
||||
# options' own `default`, because the controller's minted client secret
|
||||
# only exists on the host authelia ran its first boot on — so they belong
|
||||
# to the mode that asserts this box is the whole deployment.
|
||||
#
|
||||
# Deriving them from `deploy.nats` / `deploy.authelia`
|
||||
# inside those defaults is the mixing this file exists to prevent: the
|
||||
# option would be describing a deployment shape instead of describing
|
||||
# itself, and "what does all-local turn on?" would stop having one
|
||||
# answer.
|
||||
#
|
||||
# ⚠️ Must live INSIDE this attrset, not as a second
|
||||
# `config.services.hyperhive.swarm.…` path beside it — written that
|
||||
# way the two definitions of `swarm` collide and the nested one is
|
||||
# silently lost. The gate caught exactly that: mode on, `natsUrl`
|
||||
# still "".
|
||||
#
|
||||
# The *requirement* stays in `swarm-controller.nix` as an assertion:
|
||||
# needing a queue is the controller's own property in every topology,
|
||||
# and only the convenience is local.
|
||||
controller.queue.natsUrl = lib.mkIf cfg.deploy.singleHostSwarm (
|
||||
lib.mkDefault "tls://${config.services.hyperhive.swarm.nats.domain}:${toString config.services.hyperhive.swarm.nats.port}"
|
||||
);
|
||||
};
|
||||
|
||||
# The controller is asserted by the MODE and by nothing else. Its own
|
||||
|
|
|
|||
Loading…
Reference in a new issue