Watch
0
0
Fork
You've already forked hyperhive
0

forge: always behind the gateway; drop behindGateway

The forge always sits behind the gateway, so `deploy.forgejo.behindGateway`
(and its `swarm.forge.behindGateway` rename alias) is removed and its
true-branch behaviour is now unconditional within `deploy.forgejo.enable`:
https ROOT_URL on the gateway's httpsPort, the forge vhost and local DNS
name, the swarm-ui quick link, the published metrics scrape target, forgejo
metrics, the authelia `/metrics` rule, and `publicUrl` defaulting to
`https://<forge.domain>`.

Removed with it: the direct-port `http://<domain>:<httpPort>/` ROOT_URL
branch, the hive-ci assertion that the option is true, the core-toggle
cases that only exercised the false branch (the services-leaf case reads
`bare`, which never enabled the forge either). `hivectl open forge` now
points at `swarm.forge.publicUrl`, which can still be set to null.

Refs #4885
This commit is contained in:
atlas 2026-10-02 17:17:12 +02:00 • committed by mara
commit ac592a5d23
13 changed files with 89 additions and 213 deletions

View file

@ -52,10 +52,6 @@ let
deploy.forgejo.ci.enable = true;
};
# A hive whose one gateway-published swarm service sits on another host:
# every swarm name still configured, not one of them served here.
forgeElsewhere = hive { deploy.forgejo.behindGateway = false; };
# A priority collision is a property of the *option*, not
# of the merged value's interior — nix throws the moment the value is
# demanded at all, so `seq`-ing each `serviceConfig` value to WHNF is
@ -72,31 +68,12 @@ let
builtins.foldl' (acc: v: builtins.seq v acc) true vals;
cases = [
{
# Both halves matter. The equality is the "no longer consults the central
# toggle" half; the literal is the "and still renders what it always
# did" half, which an equality on its own would let drift to `false` in
# lockstep.
name = "the forge's behindGateway default is true regardless of the central toggle";
ok =
bare.services.hyperhive.deploy.forgejo.behindGateway == true
&& centralToggleOff.services.hyperhive.deploy.forgejo.behindGateway == true;
}
{
# Downstream of the one above — publicUrl reads `behindGateway`, so it
# tracked the central toggle transitively as well as directly. The domain
# is the stub's swarm domain, which both fixtures share.
name = "the forge's publicUrl default follows behindGateway alone, not the central toggle";
# The domain is the stub's swarm domain, which both fixtures share.
name = "the forge's publicUrl default does not consult the central toggle";
ok =
bare.services.hyperhive.swarm.forge.publicUrl == "https://forge.t.local"
&& centralToggleOff.services.hyperhive.swarm.forge.publicUrl == "https://forge.t.local";
}
{
# And that it still tracks `behindGateway` at all: without this arm the
# case above passes just as well for a default hardcoded to the URL.
name = "the forge's publicUrl default is still null with behindGateway off";
ok =
(hive { deploy.forgejo.behindGateway = false; }).services.hyperhive.swarm.forge.publicUrl == null;
}
{
# The controller's token path follows where the forge runs
# (./forge-placement.nix), never the central toggle: a forge host with
@ -226,9 +203,9 @@ let
# vhosts are the hive leaf's, which this host still signs.
name = "a host fronting none of the swarm's service names requests no services leaf";
ok =
forgeElsewhere.services.hyperhive.swarm.localServiceDomains == [ ]
&& forgeElsewhere.services.hyperhive.swarm.serviceDomains != [ ]
&& lib.hasInfix "want_svc=0" forgeElsewhere.systemd.services.swarm-services-cert.script;
bare.services.hyperhive.swarm.localServiceDomains == [ ]
&& bare.services.hyperhive.swarm.serviceDomains != [ ]
&& lib.hasInfix "want_svc=0" bare.systemd.services.swarm-services-cert.script;
}
{
# nixos asserts when a vhost declares both, so this is also a