swarm: default every queue URL to the queue's name on every hive
A remote hive dialled nothing until an operator copied the queue's URL into it, though the URL is the same string everywhere. statusPublish.natsUrl, queue.agentNatsUrl and controller.queue.natsUrl now default to tls://<swarm.nats.domain>:<port> unconditionally. The statusPublish assertion treated a URL without a secret as a half config. With the URL a default on every hive, only the secret claims publishing: the assertion now refuses a secret without a URL or token endpoint, and hive-c0re's status environment is gated on the secret too, so a hive without one publishes nothing instead of reading a missing credential.
This commit is contained in:
parent
0081d75c86
commit
a5259146dc
8 changed files with 220 additions and 129 deletions
|
|
@ -17,6 +17,7 @@ let
|
|||
cfg = config.services.hyperhive.swarm.controller;
|
||||
deployCfg = config.services.hyperhive.deploy;
|
||||
autheliaCfg = config.services.hyperhive.swarm.authelia;
|
||||
natsCfg = config.services.hyperhive.swarm.nats;
|
||||
|
||||
# Where the secret store is, and whether this host holds the controller's
|
||||
# own leaf for it. ⚠️ The controller's pair, NOT `deploy.bao.clientCertFile`
|
||||
|
|
@ -364,18 +365,18 @@ in
|
|||
queue = {
|
||||
natsUrl = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "";
|
||||
default = "tls://${natsCfg.domain}:${toString natsCfg.port}";
|
||||
defaultText = lib.literalExpression ''"tls://''${swarm.nats.domain}:''${swarm.nats.port}"'';
|
||||
example = "tls://nats.example.com:4222";
|
||||
description = ''
|
||||
Where the controller reaches the swarm queue.
|
||||
|
||||
Defaults to the queue's name, which is the same URL on every
|
||||
host: the queue's own host resolves it locally, and any other
|
||||
through the operator's DNS.
|
||||
|
||||
Empty means unset, which the assertion below refuses — a
|
||||
controller with no queue is not a lighter controller.
|
||||
|
||||
`singleHostSwarm` fills this in with
|
||||
`tls://<swarm.nats.domain>:<port>`. That derivation lives with the
|
||||
mode rather than here, so this option describes itself rather than
|
||||
a deployment shape.
|
||||
'';
|
||||
};
|
||||
|
||||
|
|
@ -764,8 +765,8 @@ in
|
|||
message = ''
|
||||
services.hyperhive.swarm.controller.queue.natsUrl is unset.
|
||||
|
||||
`singleHostSwarm` fills it in with the queue's name. A controller
|
||||
in any other deployment has to be told the URL.
|
||||
It defaults to the queue's name; something in this configuration
|
||||
set it to "". Remove that setting, or set the URL.
|
||||
'';
|
||||
}
|
||||
{
|
||||
|
|
|
|||
Loading…
Reference in a new issue