swarm: default every queue URL to the queue's name on every hive
A remote hive dialled nothing until an operator copied the queue's URL into it, though the URL is the same string everywhere. statusPublish.natsUrl, queue.agentNatsUrl and controller.queue.natsUrl now default to tls://<swarm.nats.domain>:<port> unconditionally. The statusPublish assertion treated a URL without a secret as a half config. With the URL a default on every hive, only the secret claims publishing: the assertion now refuses a secret without a URL or token endpoint, and hive-c0re's status environment is gated on the secret too, so a hive without one publishes nothing instead of reading a missing credential.
This commit is contained in:
parent
0081d75c86
commit
a5259146dc
8 changed files with 220 additions and 129 deletions
|
|
@ -42,6 +42,10 @@ let
|
|||
# renders the same absences `bare` does.
|
||||
centralToggleOff = hive { enable = false; };
|
||||
|
||||
# Every hive defaults the agents' queue address to the queue's name, so the
|
||||
# only hive without one is a hive told to have none.
|
||||
noAgentQueue = hive { deploy.hive-controller.queue.agentNatsUrl = null; };
|
||||
|
||||
withCi = hive { deploy.forgejo.ci.enable = true; };
|
||||
|
||||
# A priority collision is a property of the *option*, not
|
||||
|
|
@ -149,13 +153,13 @@ let
|
|||
}
|
||||
{
|
||||
# The absence arm, and what makes the two above able to fail: a hive
|
||||
# with no queue address must forward neither coordinate, because half a
|
||||
# pair reaches the harness as a partial configuration rather than as
|
||||
# none.
|
||||
name = "a hive with no swarm queue forwards no agent queue coordinates";
|
||||
# with no queue address for its agents must forward neither coordinate,
|
||||
# because half a pair reaches the harness as a partial configuration
|
||||
# rather than as none.
|
||||
name = "a hive with no agent queue address forwards no agent queue coordinates";
|
||||
ok =
|
||||
let
|
||||
e = bare.systemd.services.hive-c0re.environment;
|
||||
e = noAgentQueue.systemd.services.hive-c0re.environment;
|
||||
in
|
||||
!(e ? HIVE_AGENT_NATS_URL) && !(e ? HIVE_AGENT_OIDC_TOKEN_ENDPOINT);
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in a new issue