ops: update option pointers after otel split
Four comments pointed at ./swarm-otel.nix for something the split moved to ./swarm-otel-service.nix: `domain` (otel.nix), `domainBase` (swarm-ui.nix), the `clientId`/`audience` options (glue-swarm-otel-oidc-client.nix), and `producerName` (swarm-otel.nix's own "Read-only option below"). Every other pointer to ./swarm-otel.nix names its `config` block, units, exporters, authenticators or assertions, which stayed. Refs #3742
This commit is contained in:
parent
3a0a7346b1
commit
a5eb3c15c4
4 changed files with 9 additions and 9 deletions
|
|
@ -34,8 +34,8 @@ in
|
||||||
{
|
{
|
||||||
config = lib.mkIf deployCfg.authelia.enable {
|
config = lib.mkIf deployCfg.authelia.enable {
|
||||||
# One declaration, two readers: `clientId` and `audience` are read-only
|
# One declaration, two readers: `clientId` and `audience` are read-only
|
||||||
# options ./swarm-otel.nix derives from the scrape/push targets it owns,
|
# options ./swarm-otel-service.nix derives from the scrape/push targets it
|
||||||
# so this file states neither formula a second time.
|
# owns, so this file states neither formula a second time.
|
||||||
services.hyperhive.swarm.authelia.oidc.clients = [
|
services.hyperhive.swarm.authelia.oidc.clients = [
|
||||||
{
|
{
|
||||||
id = otelCfg.clientId;
|
id = otelCfg.clientId;
|
||||||
|
|
|
||||||
|
|
@ -21,7 +21,7 @@
|
||||||
}:
|
}:
|
||||||
let
|
let
|
||||||
# This tier now reaches the swarm's collector by name through the
|
# This tier now reaches the swarm's collector by name through the
|
||||||
# gateway (`swarm-otel.nix`'s `domain`) instead of a loopback URL, so it
|
# gateway (`swarm-otel-service.nix`'s `domain`) instead of a loopback URL, so it
|
||||||
# needs the same hive-CA trust every other host consumer of an `https://`
|
# needs the same hive-CA trust every other host consumer of an `https://`
|
||||||
# swarm-service name needs — see `swarm-controller.nix` for the sibling
|
# swarm-service name needs — see `swarm-controller.nix` for the sibling
|
||||||
# wiring this copies.
|
# wiring this copies.
|
||||||
|
|
|
||||||
|
|
@ -35,10 +35,10 @@ let
|
||||||
# that reserves it is checking the same string the config emits. A literal
|
# that reserves it is checking the same string the config emits. A literal
|
||||||
# repeated at each site would let the guard and the config drift apart, which
|
# repeated at each site would let the guard and the config drift apart, which
|
||||||
# is the failure this guard exists to prevent.
|
# is the failure this guard exists to prevent.
|
||||||
# Read-only option below, not a bare literal — `swarm-controller.nix` needs
|
# The read-only `producerName` option in ./swarm-otel-service.nix, not a bare
|
||||||
# the identical string to build the same audience/endpoint, and a value
|
# literal — `swarm-controller.nix` needs the identical string to build the
|
||||||
# bound once here (rather than copy-pasted at both sites) is the only way
|
# same audience/endpoint, and a value bound once (rather than copy-pasted at
|
||||||
# the two can't drift apart.
|
# both sites) is the only way the two can't drift apart.
|
||||||
swarmTierName = cfg.producerName;
|
swarmTierName = cfg.producerName;
|
||||||
|
|
||||||
# The SECOND swarm-tier producer: the collector inside the secret store's
|
# The SECOND swarm-tier producer: the collector inside the secret store's
|
||||||
|
|
|
||||||
|
|
@ -56,8 +56,8 @@ let
|
||||||
|
|
||||||
# The swarm apex this UI answers on. Total on a null domain (`.invalid`,
|
# The swarm apex this UI answers on. Total on a null domain (`.invalid`,
|
||||||
# RFC 2606) so `hive-network.nix`'s required-domain assertion is what fires,
|
# RFC 2606) so `hive-network.nix`'s required-domain assertion is what fires,
|
||||||
# rather than a coercion error from here — same idiom as `swarm-otel.nix`'s
|
# rather than a coercion error from here — same idiom as
|
||||||
# `domainBase`.
|
# `swarm-otel-service.nix`'s `domainBase`.
|
||||||
apex = if swarmCfg.domain == null then "swarm.invalid" else swarmCfg.domain;
|
apex = if swarmCfg.domain == null then "swarm.invalid" else swarmCfg.domain;
|
||||||
in
|
in
|
||||||
{
|
{
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue