nix: ship the journals of the units an apply can leave failed
The units on the path a deploy takes to TLS, the store's grants and the swarm collector itself were not on the host collector's journald allowlist, so an ingest outage one of them caused showed in the store only as every source going quiet at once. Each module names its own units, per the option's rule: - hive-tls.nix: hive-tls-ca, swarm-services-cert - hive-gateway: hive-gateway-self-signed-cert (self-signed mode only) - swarm-bao.nix: the seven grant units beside swarm-bao-services-issuer-policy - swarm-otel.nix: container@<machine>, and nixos-rebuild-switch-to-configuration, the transient unit nixos-rebuild runs the activation in and whose syslog lines carry its status The module-eval arm pins each unit as both listed and defined, since a listed name that matches nothing is silent.
This commit is contained in:
parent
fdb847cd87
commit
aa719da571
5 changed files with 77 additions and 3 deletions
|
|
@ -129,8 +129,13 @@ in
|
|||
# Every request to every hyperhive service passes through here, so this
|
||||
# is the one unit that can say a service was unreachable rather than
|
||||
# merely quiet. Named even on hives that run no swarm collector: the
|
||||
# option is inert unless one is collecting on this host.
|
||||
services.hyperhive.swarm.otel.journaldUnits = [ "nginx" ];
|
||||
# option is inert unless one is collecting on this host. nginx
|
||||
# `Requires=` the self-signed copy, so its journal is the other half of
|
||||
# why nginx did not start.
|
||||
services.hyperhive.swarm.otel.journaldUnits = [
|
||||
"nginx"
|
||||
]
|
||||
++ lib.optional useSelfSigned "hive-gateway-self-signed-cert";
|
||||
|
||||
assertions = [
|
||||
{
|
||||
|
|
|
|||
Loading…
Reference in a new issue