diff --git a/nix/host-modules/glue-swarm-otel-oidc-client.nix b/nix/host-modules/glue-swarm-otel-oidc-client.nix index d38303e4..6c51d214 100644 --- a/nix/host-modules/glue-swarm-otel-oidc-client.nix +++ b/nix/host-modules/glue-swarm-otel-oidc-client.nix @@ -34,8 +34,8 @@ in { config = lib.mkIf deployCfg.authelia.enable { # One declaration, two readers: `clientId` and `audience` are read-only - # options ./swarm-otel.nix derives from the scrape/push targets it owns, - # so this file states neither formula a second time. + # options ./swarm-otel-service.nix derives from the scrape/push targets it + # owns, so this file states neither formula a second time. services.hyperhive.swarm.authelia.oidc.clients = [ { id = otelCfg.clientId; diff --git a/nix/host-modules/otel.nix b/nix/host-modules/otel.nix index 84e6a81a..d1c8b904 100644 --- a/nix/host-modules/otel.nix +++ b/nix/host-modules/otel.nix @@ -21,7 +21,7 @@ }: let # This tier now reaches the swarm's collector by name through the - # gateway (`swarm-otel.nix`'s `domain`) instead of a loopback URL, so it + # gateway (`swarm-otel-service.nix`'s `domain`) instead of a loopback URL, so it # needs the same hive-CA trust every other host consumer of an `https://` # swarm-service name needs — see `swarm-controller.nix` for the sibling # wiring this copies. diff --git a/nix/host-modules/swarm-otel.nix b/nix/host-modules/swarm-otel.nix index c0d6ffad..5dc3b23f 100644 --- a/nix/host-modules/swarm-otel.nix +++ b/nix/host-modules/swarm-otel.nix @@ -35,10 +35,10 @@ let # that reserves it is checking the same string the config emits. A literal # repeated at each site would let the guard and the config drift apart, which # is the failure this guard exists to prevent. - # Read-only option below, not a bare literal — `swarm-controller.nix` needs - # the identical string to build the same audience/endpoint, and a value - # bound once here (rather than copy-pasted at both sites) is the only way - # the two can't drift apart. + # The read-only `producerName` option in ./swarm-otel-service.nix, not a bare + # literal — `swarm-controller.nix` needs the identical string to build the + # same audience/endpoint, and a value bound once (rather than copy-pasted at + # both sites) is the only way the two can't drift apart. swarmTierName = cfg.producerName; # The SECOND swarm-tier producer: the collector inside the secret store's diff --git a/nix/host-modules/swarm-ui.nix b/nix/host-modules/swarm-ui.nix index f196d0b2..90443482 100644 --- a/nix/host-modules/swarm-ui.nix +++ b/nix/host-modules/swarm-ui.nix @@ -56,8 +56,8 @@ let # The swarm apex this UI answers on. Total on a null domain (`.invalid`, # RFC 2606) so `hive-network.nix`'s required-domain assertion is what fires, - # rather than a coercion error from here — same idiom as `swarm-otel.nix`'s - # `domainBase`. + # rather than a coercion error from here — same idiom as + # `swarm-otel-service.nix`'s `domainBase`. apex = if swarmCfg.domain == null then "swarm.invalid" else swarmCfg.domain; in {