forge: always behind the gateway; drop behindGateway
The forge always sits behind the gateway, so `deploy.forgejo.behindGateway` (and its `swarm.forge.behindGateway` rename alias) is removed and its true-branch behaviour is now unconditional within `deploy.forgejo.enable`: https ROOT_URL on the gateway's httpsPort, the forge vhost and local DNS name, the swarm-ui quick link, the published metrics scrape target, forgejo metrics, the authelia `/metrics` rule, and `publicUrl` defaulting to `https://<forge.domain>`. Removed with it: the direct-port `http://<domain>:<httpPort>/` ROOT_URL branch, the hive-ci assertion that the option is true, the core-toggle cases that only exercised the false branch (the services-leaf case reads `bare`, which never enabled the forge either). `hivectl open forge` now points at `swarm.forge.publicUrl`, which can still be set to null. Refs #4885
This commit is contained in:
parent
a40c0026cf
commit
ac592a5d23
13 changed files with 89 additions and 213 deletions
|
|
@ -10,7 +10,6 @@ let
|
|||
cfg = config.services.hyperhive.swarm.forge;
|
||||
gatewayCfg = config.services.hyperhive.gateway;
|
||||
swarmDomain = config.services.hyperhive.swarm.domain;
|
||||
deployCfg = config.services.hyperhive.deploy;
|
||||
|
||||
# Forgejo's name for the login source. Duplicated in ./default.nix, which
|
||||
# registers the source under it.
|
||||
|
|
@ -24,13 +23,10 @@ let
|
|||
# Forgejo's `ROOT_URL`, duplicated from ./default.nix, which documents its
|
||||
# shape.
|
||||
defaultRootUrl =
|
||||
if deployCfg.forgejo.behindGateway then
|
||||
let
|
||||
portSuffix = if gatewayCfg.httpsPort == 443 then "" else ":${toString gatewayCfg.httpsPort}";
|
||||
in
|
||||
"https://${cfg.domain}${portSuffix}/"
|
||||
else
|
||||
"http://${cfg.domain}:${toString cfg.httpPort}/";
|
||||
let
|
||||
portSuffix = if gatewayCfg.httpsPort == 443 then "" else ":${toString gatewayCfg.httpsPort}";
|
||||
in
|
||||
"https://${cfg.domain}${portSuffix}/";
|
||||
effectiveRootUrl = if cfg.rootUrl != null then cfg.rootUrl else defaultRootUrl;
|
||||
in
|
||||
{
|
||||
|
|
@ -94,8 +90,8 @@ in
|
|||
description = ''
|
||||
Public hostname for the forge. Doubles as both the forgejo
|
||||
`DOMAIN` setting (clone URLs forgejo advertises) AND the
|
||||
gateway vhost server-name when `deploy.forgejo.behindGateway = true`
|
||||
(sub-domain routing — see `docs/networking/gateway.md`).
|
||||
gateway vhost server-name (sub-domain routing — see
|
||||
`docs/networking/gateway.md`).
|
||||
|
||||
Defaults to `forge.''${services.hyperhive.swarm.domain}` — the
|
||||
swarm's domain, not this hive's, because a swarm runs **one**
|
||||
|
|
@ -116,10 +112,8 @@ in
|
|||
|
||||
publicUrl = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.str;
|
||||
default = if deployCfg.forgejo.behindGateway then "https://${cfg.domain}" else null;
|
||||
defaultText = lib.literalExpression ''
|
||||
if behindGateway then "https://''${domain}" else null
|
||||
'';
|
||||
default = "https://${cfg.domain}";
|
||||
defaultText = lib.literalExpression ''"https://''${domain}"'';
|
||||
example = "https://forge.example.com";
|
||||
description = ''
|
||||
Browser-facing forge URL the dashboard uses to build clickable
|
||||
|
|
@ -127,20 +121,12 @@ in
|
|||
the approval-queue's "review PR on forge" link) — sourced into
|
||||
every agent container + hive-c0re as `HIVE_FORGE_PUBLIC_URL`.
|
||||
|
||||
Defaults to `https://''${cfg.domain}` when `deploy.forgejo.behindGateway =
|
||||
true` (the gateway vhost is genuinely reachable at that URL)
|
||||
and `null` otherwise. When `null`, the dashboard **hides**
|
||||
forge links rather than guessing one — see
|
||||
`docs/web-ui/dashboard.md::H0M3 page` for the rationale (a
|
||||
link built from the operator's own browser hostname + a
|
||||
container port is only an accident away from wrong on any
|
||||
deployment that isn't plain localhost).
|
||||
|
||||
**Set this explicitly if `deploy.forgejo.behindGateway = false`** and the
|
||||
forge is still reachable at a stable URL you want linked from
|
||||
the dashboard (e.g. `http://<lan-host>:''${toString cfg.httpPort}`
|
||||
for an all-LAN deployment) — leaving it unset there means the
|
||||
dashboard's forge links are simply absent, not broken.
|
||||
Defaults to `https://''${cfg.domain}`, the gateway vhost. When
|
||||
`null`, the dashboard **hides** forge links rather than
|
||||
guessing one — see `docs/web-ui/dashboard.md::H0M3 page` for
|
||||
the rationale (a link built from the operator's own browser
|
||||
hostname + a container port is only an accident away from
|
||||
wrong on any deployment that isn't plain localhost).
|
||||
'';
|
||||
};
|
||||
|
||||
|
|
@ -150,20 +136,15 @@ in
|
|||
example = "https://forge.example.com/";
|
||||
description = ''
|
||||
Override the auto-derived forgejo `ROOT_URL`. When `null`
|
||||
(default), `ROOT_URL` is derived from `cfg.domain` + gateway
|
||||
state, including the scheme:
|
||||
(default), `ROOT_URL` is `https://''${cfg.domain}/`. The gateway
|
||||
always terminates TLS (self-signed is the implicit floor when no
|
||||
`gateway.tls.certDir` / ACME is set), so the forge is always
|
||||
advertised over https. A non-canonical `gateway.httpsPort` is
|
||||
appended as `:<port>`.
|
||||
|
||||
- `deploy.forgejo.behindGateway = true` → `https://''${cfg.domain}/`. The gateway
|
||||
always terminates TLS (self-signed is the implicit floor when no
|
||||
`gateway.tls.certDir` / ACME is set), so the forge is always
|
||||
advertised over https. A non-canonical `gateway.httpsPort` is
|
||||
appended as `:<port>`.
|
||||
- `deploy.forgejo.behindGateway = false` → `http://''${cfg.domain}:''${cfg.httpPort}/`
|
||||
|
||||
The TLS scheme is derived automatically now, so you only need to
|
||||
set this for a genuinely bespoke shape (e.g. an external reverse
|
||||
proxy on a different host/path). Must end with `/` per forgejo's
|
||||
`ROOT_URL` contract.
|
||||
Set this only for a genuinely bespoke shape (e.g. an external
|
||||
reverse proxy on a different host/path). Must end with `/` per
|
||||
forgejo's `ROOT_URL` contract.
|
||||
'';
|
||||
};
|
||||
|
||||
|
|
@ -202,11 +183,10 @@ in
|
|||
format.
|
||||
|
||||
⚠️ With {option}`services.hyperhive.swarm.forge.rootUrl` unset,
|
||||
`ROOT_URL` follows
|
||||
{option}`services.hyperhive.deploy.forgejo.behindGateway` and
|
||||
the gateway's `httpsPort`, which are per-host. An authelia host
|
||||
that is not the forge's host renders the forge's callback only
|
||||
if the two agree on them; set `rootUrl` if they do not.
|
||||
`ROOT_URL` follows the gateway's `httpsPort`, which is
|
||||
per-host. An authelia host that is not the forge's host renders
|
||||
the forge's callback only if the two agree on it; set `rootUrl`
|
||||
if they do not.
|
||||
'';
|
||||
};
|
||||
# The secret half is a path on the host that runs the forge, so it
|
||||
|
|
|
|||
Loading…
Reference in a new issue