Watch
0
0
Fork
You've already forked hyperhive
0

ops: update option pointers after otel split

Four comments pointed at ./swarm-otel.nix for something the split moved
to ./swarm-otel-service.nix: `domain` (otel.nix), `domainBase`
(swarm-ui.nix), the `clientId`/`audience` options
(glue-swarm-otel-oidc-client.nix), and `producerName` (swarm-otel.nix's
own "Read-only option below"). Every other pointer to ./swarm-otel.nix
names its `config` block, units, exporters, authenticators or
assertions, which stayed.

Refs #3742
This commit is contained in:
atlas 2026-10-01 10:13:03 +02:00 • committed by mara
commit a5eb3c15c4
4 changed files with 9 additions and 9 deletions

View file

@ -34,8 +34,8 @@ in
{ {
config = lib.mkIf deployCfg.authelia.enable { config = lib.mkIf deployCfg.authelia.enable {
# One declaration, two readers: `clientId` and `audience` are read-only # One declaration, two readers: `clientId` and `audience` are read-only
# options ./swarm-otel.nix derives from the scrape/push targets it owns, # options ./swarm-otel-service.nix derives from the scrape/push targets it
# so this file states neither formula a second time. # owns, so this file states neither formula a second time.
services.hyperhive.swarm.authelia.oidc.clients = [ services.hyperhive.swarm.authelia.oidc.clients = [
{ {
id = otelCfg.clientId; id = otelCfg.clientId;

View file

@ -21,7 +21,7 @@
}: }:
let let
# This tier now reaches the swarm's collector by name through the # This tier now reaches the swarm's collector by name through the
# gateway (`swarm-otel.nix`'s `domain`) instead of a loopback URL, so it # gateway (`swarm-otel-service.nix`'s `domain`) instead of a loopback URL, so it
# needs the same hive-CA trust every other host consumer of an `https://` # needs the same hive-CA trust every other host consumer of an `https://`
# swarm-service name needs — see `swarm-controller.nix` for the sibling # swarm-service name needs — see `swarm-controller.nix` for the sibling
# wiring this copies. # wiring this copies.

View file

@ -35,10 +35,10 @@ let
# that reserves it is checking the same string the config emits. A literal # that reserves it is checking the same string the config emits. A literal
# repeated at each site would let the guard and the config drift apart, which # repeated at each site would let the guard and the config drift apart, which
# is the failure this guard exists to prevent. # is the failure this guard exists to prevent.
# Read-only option below, not a bare literal — `swarm-controller.nix` needs # The read-only `producerName` option in ./swarm-otel-service.nix, not a bare
# the identical string to build the same audience/endpoint, and a value # literal — `swarm-controller.nix` needs the identical string to build the
# bound once here (rather than copy-pasted at both sites) is the only way # same audience/endpoint, and a value bound once (rather than copy-pasted at
# the two can't drift apart. # both sites) is the only way the two can't drift apart.
swarmTierName = cfg.producerName; swarmTierName = cfg.producerName;
# The SECOND swarm-tier producer: the collector inside the secret store's # The SECOND swarm-tier producer: the collector inside the secret store's

View file

@ -56,8 +56,8 @@ let
# The swarm apex this UI answers on. Total on a null domain (`.invalid`, # The swarm apex this UI answers on. Total on a null domain (`.invalid`,
# RFC 2606) so `hive-network.nix`'s required-domain assertion is what fires, # RFC 2606) so `hive-network.nix`'s required-domain assertion is what fires,
# rather than a coercion error from here — same idiom as `swarm-otel.nix`'s # rather than a coercion error from here — same idiom as
# `domainBase`. # `swarm-otel-service.nix`'s `domainBase`.
apex = if swarmCfg.domain == null then "swarm.invalid" else swarmCfg.domain; apex = if swarmCfg.domain == null then "swarm.invalid" else swarmCfg.domain;
in in
{ {