forge: always behind the gateway; drop behindGateway
The forge always sits behind the gateway, so `deploy.forgejo.behindGateway` (and its `swarm.forge.behindGateway` rename alias) is removed and its true-branch behaviour is now unconditional within `deploy.forgejo.enable`: https ROOT_URL on the gateway's httpsPort, the forge vhost and local DNS name, the swarm-ui quick link, the published metrics scrape target, forgejo metrics, the authelia `/metrics` rule, and `publicUrl` defaulting to `https://<forge.domain>`. Removed with it: the direct-port `http://<domain>:<httpPort>/` ROOT_URL branch, the hive-ci assertion that the option is true, the core-toggle cases that only exercised the false branch (the services-leaf case reads `bare`, which never enabled the forge either). `hivectl open forge` now points at `swarm.forge.publicUrl`, which can still be set to null. Refs #4885
This commit is contained in:
parent
a40c0026cf
commit
ac592a5d23
13 changed files with 89 additions and 213 deletions
|
|
@ -52,10 +52,6 @@ let
|
|||
deploy.forgejo.ci.enable = true;
|
||||
};
|
||||
|
||||
# A hive whose one gateway-published swarm service sits on another host:
|
||||
# every swarm name still configured, not one of them served here.
|
||||
forgeElsewhere = hive { deploy.forgejo.behindGateway = false; };
|
||||
|
||||
# A priority collision is a property of the *option*, not
|
||||
# of the merged value's interior — nix throws the moment the value is
|
||||
# demanded at all, so `seq`-ing each `serviceConfig` value to WHNF is
|
||||
|
|
@ -72,31 +68,12 @@ let
|
|||
builtins.foldl' (acc: v: builtins.seq v acc) true vals;
|
||||
cases = [
|
||||
{
|
||||
# Both halves matter. The equality is the "no longer consults the central
|
||||
# toggle" half; the literal is the "and still renders what it always
|
||||
# did" half, which an equality on its own would let drift to `false` in
|
||||
# lockstep.
|
||||
name = "the forge's behindGateway default is true regardless of the central toggle";
|
||||
ok =
|
||||
bare.services.hyperhive.deploy.forgejo.behindGateway == true
|
||||
&& centralToggleOff.services.hyperhive.deploy.forgejo.behindGateway == true;
|
||||
}
|
||||
{
|
||||
# Downstream of the one above — publicUrl reads `behindGateway`, so it
|
||||
# tracked the central toggle transitively as well as directly. The domain
|
||||
# is the stub's swarm domain, which both fixtures share.
|
||||
name = "the forge's publicUrl default follows behindGateway alone, not the central toggle";
|
||||
# The domain is the stub's swarm domain, which both fixtures share.
|
||||
name = "the forge's publicUrl default does not consult the central toggle";
|
||||
ok =
|
||||
bare.services.hyperhive.swarm.forge.publicUrl == "https://forge.t.local"
|
||||
&& centralToggleOff.services.hyperhive.swarm.forge.publicUrl == "https://forge.t.local";
|
||||
}
|
||||
{
|
||||
# And that it still tracks `behindGateway` at all: without this arm the
|
||||
# case above passes just as well for a default hardcoded to the URL.
|
||||
name = "the forge's publicUrl default is still null with behindGateway off";
|
||||
ok =
|
||||
(hive { deploy.forgejo.behindGateway = false; }).services.hyperhive.swarm.forge.publicUrl == null;
|
||||
}
|
||||
{
|
||||
# The controller's token path follows where the forge runs
|
||||
# (./forge-placement.nix), never the central toggle: a forge host with
|
||||
|
|
@ -226,9 +203,9 @@ let
|
|||
# vhosts are the hive leaf's, which this host still signs.
|
||||
name = "a host fronting none of the swarm's service names requests no services leaf";
|
||||
ok =
|
||||
forgeElsewhere.services.hyperhive.swarm.localServiceDomains == [ ]
|
||||
&& forgeElsewhere.services.hyperhive.swarm.serviceDomains != [ ]
|
||||
&& lib.hasInfix "want_svc=0" forgeElsewhere.systemd.services.swarm-services-cert.script;
|
||||
bare.services.hyperhive.swarm.localServiceDomains == [ ]
|
||||
&& bare.services.hyperhive.swarm.serviceDomains != [ ]
|
||||
&& lib.hasInfix "want_svc=0" bare.systemd.services.swarm-services-cert.script;
|
||||
}
|
||||
{
|
||||
# nixos asserts when a vhost declares both, so this is also a
|
||||
|
|
|
|||
Loading…
Reference in a new issue