Watch
0
0
Fork
You've already forked hyperhive
0

forge: always behind the gateway; drop behindGateway

The forge always sits behind the gateway, so `deploy.forgejo.behindGateway`
(and its `swarm.forge.behindGateway` rename alias) is removed and its
true-branch behaviour is now unconditional within `deploy.forgejo.enable`:
https ROOT_URL on the gateway's httpsPort, the forge vhost and local DNS
name, the swarm-ui quick link, the published metrics scrape target, forgejo
metrics, the authelia `/metrics` rule, and `publicUrl` defaulting to
`https://<forge.domain>`.

Removed with it: the direct-port `http://<domain>:<httpPort>/` ROOT_URL
branch, the hive-ci assertion that the option is true, the core-toggle
cases that only exercised the false branch (the services-leaf case reads
`bare`, which never enabled the forge either). `hivectl open forge` now
points at `swarm.forge.publicUrl`, which can still be set to null.

Refs #4885
This commit is contained in:
atlas 2026-10-02 17:17:12 +02:00 • committed by mara
commit ac592a5d23
13 changed files with 89 additions and 213 deletions

View file

@ -52,8 +52,7 @@ let
# Private network namespace, attached to the hive bridge so the
# runner reaches the forge via the gateway — and cannot reach
# host-loopback (127.0.0.1:7000 dashboard, raw forge port, etc.).
# Requires `deploy.forgejo.behindGateway = true` (asserted in the
# config block below). See docs/networking/network.md.
# See docs/networking/network.md.
privateNetwork = true;
in
{
@ -161,22 +160,7 @@ in
};
config = lib.mkIf cfg.enable {
# `deploy.forgejo.behindGateway = true` (the default) is required because
# the CI container uses private networking and reaches the forge through
# the gateway vhost. Without the gateway vhost there is no HTTP
# listener for `forgeCfg.domain` on the bridge that the runner can
# connect to.
assertions = [
{
assertion = forgeDeployCfg.behindGateway;
message = ''
services.hyperhive.deploy.forgejo.ci.enable requires
services.hyperhive.deploy.forgejo.behindGateway = true.
The CI container runs with a private network namespace and
reaches the forge through the gateway vhost on the bridge IP.
Set behindGateway = true (it is the default).
'';
}
{
# The runner reaches the forge through THIS host's gateway, and
# hive-c0re registers it through the local forge container; neither