Watch
0
0
Fork
You've already forked hyperhive
0

ops: update option pointers after otel split

Four comments pointed at ./swarm-otel.nix for something the split moved
to ./swarm-otel-service.nix: `domain` (otel.nix), `domainBase`
(swarm-ui.nix), the `clientId`/`audience` options
(glue-swarm-otel-oidc-client.nix), and `producerName` (swarm-otel.nix's
own "Read-only option below"). Every other pointer to ./swarm-otel.nix
names its `config` block, units, exporters, authenticators or
assertions, which stayed.

Refs #3742
This commit is contained in:
atlas 2026-10-01 10:13:03 +02:00 • committed by mara
commit a5eb3c15c4
4 changed files with 9 additions and 9 deletions

View file

@ -34,8 +34,8 @@ in
{
config = lib.mkIf deployCfg.authelia.enable {
# One declaration, two readers: `clientId` and `audience` are read-only
# options ./swarm-otel.nix derives from the scrape/push targets it owns,
# so this file states neither formula a second time.
# options ./swarm-otel-service.nix derives from the scrape/push targets it
# owns, so this file states neither formula a second time.
services.hyperhive.swarm.authelia.oidc.clients = [
{
id = otelCfg.clientId;

View file

@ -21,7 +21,7 @@
}:
let
# This tier now reaches the swarm's collector by name through the
# gateway (`swarm-otel.nix`'s `domain`) instead of a loopback URL, so it
# gateway (`swarm-otel-service.nix`'s `domain`) instead of a loopback URL, so it
# needs the same hive-CA trust every other host consumer of an `https://`
# swarm-service name needs — see `swarm-controller.nix` for the sibling
# wiring this copies.

View file

@ -35,10 +35,10 @@ let
# that reserves it is checking the same string the config emits. A literal
# repeated at each site would let the guard and the config drift apart, which
# is the failure this guard exists to prevent.
# Read-only option below, not a bare literal — `swarm-controller.nix` needs
# the identical string to build the same audience/endpoint, and a value
# bound once here (rather than copy-pasted at both sites) is the only way
# the two can't drift apart.
# The read-only `producerName` option in ./swarm-otel-service.nix, not a bare
# literal — `swarm-controller.nix` needs the identical string to build the
# same audience/endpoint, and a value bound once (rather than copy-pasted at
# both sites) is the only way the two can't drift apart.
swarmTierName = cfg.producerName;
# The SECOND swarm-tier producer: the collector inside the secret store's

View file

@ -56,8 +56,8 @@ let
# The swarm apex this UI answers on. Total on a null domain (`.invalid`,
# RFC 2606) so `hive-network.nix`'s required-domain assertion is what fires,
# rather than a coercion error from here — same idiom as `swarm-otel.nix`'s
# `domainBase`.
# rather than a coercion error from here — same idiom as
# `swarm-otel-service.nix`'s `domainBase`.
apex = if swarmCfg.domain == null then "swarm.invalid" else swarmCfg.domain;
in
{