forge: always behind the gateway; drop behindGateway
The forge always sits behind the gateway, so `deploy.forgejo.behindGateway` (and its `swarm.forge.behindGateway` rename alias) is removed and its true-branch behaviour is now unconditional within `deploy.forgejo.enable`: https ROOT_URL on the gateway's httpsPort, the forge vhost and local DNS name, the swarm-ui quick link, the published metrics scrape target, forgejo metrics, the authelia `/metrics` rule, and `publicUrl` defaulting to `https://<forge.domain>`. Removed with it: the direct-port `http://<domain>:<httpPort>/` ROOT_URL branch, the hive-ci assertion that the option is true, the core-toggle cases that only exercised the false branch (the services-leaf case reads `bare`, which never enabled the forge either). `hivectl open forge` now points at `swarm.forge.publicUrl`, which can still be set to null. Refs #4885
This commit is contained in:
parent
a40c0026cf
commit
ac592a5d23
13 changed files with 89 additions and 213 deletions
|
|
@ -10,7 +10,7 @@ This host's nginx fronts the hyperhive web surfaces running on it — next to hi
|
|||
| `<hive>/agent/<name>/` | `_` | per-agent harness (UDS or TCP) | `agents.conf` (runtime-generated) |
|
||||
| `<hive>/.well-known/matrix/{client,server}` | `_` | inline JSON (no upstream) | `matrix.enable && domain != null` |
|
||||
| `<hive>/matrix/` (deprecated) | `_` | 301 → `chat.<swarm>/` | `matrix.gui.enable` |
|
||||
| `forge.<swarm>/` | `forge.<swarm>` | forgejo (`3000`) | `deploy.forgejo.behindGateway` |
|
||||
| `forge.<swarm>/` | `forge.<swarm>` | forgejo (`3000`) | `deploy.forgejo` |
|
||||
| `chat.<swarm>/_matrix/*` | `chat.<swarm>` | tuwunel (`8008`) | `matrix.gatewayHost != null` |
|
||||
| `chat.<swarm>/` | `chat.<swarm>` | fluffychat-web static | `matrix.gui.enable` |
|
||||
| `chat.<swarm>/config.json` | `chat.<swarm>` | inline JSON (FluffyChat boot config) | `matrix.gui.enable && domain != null` |
|
||||
|
|
@ -66,7 +66,7 @@ Each location carries a duplicated `auth_basic` block (separate locations don't
|
|||
`services.hyperhive.gateway.localHostsEntry = true` adds entries to the host's `/etc/hosts`:
|
||||
|
||||
- `<hive-domain>` → `127.0.0.1`
|
||||
- `forge.<swarm>` → `127.0.0.1` (when deploy.forgejo.behindGateway)
|
||||
- `forge.<swarm>` → `127.0.0.1` (when deploy.forgejo)
|
||||
- `chat.<swarm>` → `127.0.0.1` (when matrix.gatewayHost set)
|
||||
- `auth.<swarm>` → `127.0.0.1` (when deploy.authelia)
|
||||
|
||||
|
|
@ -165,9 +165,8 @@ true; the `false` branch stays as a defensive fallback for the
|
|||
env being unset. Three render sites
|
||||
flip together: the primary agent-name link, the favicon fetch
|
||||
(`<url>/icon`), and the nav-strip `container`-kind links from
|
||||
`DashboardState.links` (`GET /api/dashboard-state`). `forge`-kind nav-strip links still
|
||||
resolve against `http://<host>:3000` (separate sub-domain transition
|
||||
tracked by `deploy.forgejo.behindGateway`); `external`-kind links are
|
||||
`DashboardState.links` (`GET /api/dashboard-state`). `forge`-kind nav-strip links
|
||||
resolve against `forge_public_url`, and the dashboard hides them when it's unset; `external`-kind links are
|
||||
already absolute. See `docs/web-ui/dashboard.md::Container row` for the
|
||||
frontend-side derivation.
|
||||
|
||||
|
|
@ -385,9 +384,8 @@ the bridge), not the raw port, so no firewall hole is needed. Flip to
|
|||
- External git clients that push/pull via SSH directly to the host.
|
||||
<!-- vale write-good.Passive = YES -->
|
||||
|
||||
Forgejo served through the gateway (`deploy.forgejo.behindGateway = true`) does
|
||||
not need `openFirewall` — the gateway's own `openFirewall` option covers
|
||||
that path.
|
||||
Forgejo's gateway vhost doesn't need `openFirewall` — the gateway's own
|
||||
`openFirewall` option covers that path.
|
||||
|
||||
### `rootUrl` override
|
||||
|
||||
|
|
@ -396,17 +394,9 @@ services.hyperhive.swarm.forge.rootUrl = "https://forge.example.com/";
|
|||
```
|
||||
|
||||
`rootUrl` (default **null**) overrides the Forgejo `ROOT_URL` that's
|
||||
autoderived from `forge.domain` + gateway state. The autoderivation
|
||||
covers most cases:
|
||||
|
||||
| Shape | Autoderived `ROOT_URL` |
|
||||
|---|---|
|
||||
| `deploy.forgejo.behindGateway = true` | `https://<forge.domain>/` (port suffix omitted when `gateway.httpsPort == 443`) |
|
||||
| `deploy.forgejo.behindGateway = false` | `http://<forge.domain>:<httpPort>/` |
|
||||
|
||||
The gateway always terminates TLS, so the `behindGateway = true` case is
|
||||
always advertised over `https://`; only the direct (`behindGateway =
|
||||
false`) shape stays `http://`. Set `rootUrl` explicitly when
|
||||
autoderived as `https://<forge.domain>/`, with `:<gateway.httpsPort>`
|
||||
appended when that port isn't 443. The gateway always terminates TLS, so
|
||||
the forge is always advertised over `https://`. Set `rootUrl` explicitly when
|
||||
`forge.domain` resolves differently from the public URL, or for a
|
||||
genuinely bespoke shape (for example an external reverse proxy on a different
|
||||
host/path). Must end with `/` (Forgejo requirement; an assertion
|
||||
|
|
|
|||
|
|
@ -119,7 +119,7 @@ build can't hold the runner's single slot indefinitely).
|
|||
|
||||
## Container design
|
||||
|
||||
- **Private netns, bridge-attached**: the container runs in its own network namespace (`privateNetwork = true`, `hostBridge`) and reaches hive-forge through the gateway at `http://<forge.domain>` (resolved to the bridge IP via `networking.extraHosts`). It can't reach host-loopback services — the core dashboard at `127.0.0.1:7000` and the raw forge port are unreachable from CI. Requires `deploy.forgejo.behindGateway = true`.
|
||||
- **Private netns, bridge-attached**: the container runs in its own network namespace (`privateNetwork = true`, `hostBridge`) and reaches hive-forge through the gateway at `http://<forge.domain>` (resolved to the bridge IP via `networking.extraHosts`). It can't reach host-loopback services — the core dashboard at `127.0.0.1:7000` and the raw forge port are unreachable from CI.
|
||||
- **Non-ephemeral**: runner credentials persist across restarts (written to container's stateDir on first registration, reused thereafter).
|
||||
- **Sandbox fallback**: nspawn containers can't create user-namespaces, so nix's sandboxing would always fail. Module sets `nix.settings.sandbox-fallback = true` in the container — nix builds run unsandboxed (safe because the container is already isolated). See `docs/process/gotchas.md`.
|
||||
- **Credential isolation**: the forge admin token (`forge-core-token`) never enters the container. hive-c0re holds it and performs all forge API calls (runner validation + registration-token mint, in `forge/ci_runner.rs`); via hive-priv it writes only the runner registration token to the host env-file `/run/hive-ci/runner-token`, which the container bind-mounts read-only.
|
||||
|
|
|
|||
|
|
@ -272,6 +272,6 @@ note, not an error.
|
|||
|
||||
A surface has no URL when it isn't browser-reachable: `home` needs
|
||||
`services.hyperhive.domain`; `forge` needs
|
||||
`services.hyperhive.deploy.forgejo.behindGateway = true`; `matrix` needs
|
||||
`services.hyperhive.swarm.forge.publicUrl` (set by default); `matrix` needs
|
||||
`services.hyperhive.deploy.matrix.gui.enable = true`. In those cases the command
|
||||
exits with a hint naming the option to set.
|
||||
|
|
|
|||
Loading…
Reference in a new issue