docs: drop statements about absent things, state current behaviour
This commit is contained in:
parent
4498272276
commit
b83fdc60f3
4 changed files with 22 additions and 30 deletions
|
|
@ -13,12 +13,12 @@ catalogued below.
|
|||
Telemetry crosses two collectors, and which one you configure depends on what
|
||||
the host is:
|
||||
|
||||
| | runs where | receives from | does |
|
||||
| ------------------------------------ | ---------------------- | --------------------------------- | --------------------------------------------------------------------- |
|
||||
| **swarm tier** — `deploy.swarm-otel` | once per swarm | every hive's collector | writes the swarm's stores and exports upstream |
|
||||
| **hive tier** — `otel.enable` | every hive with agents | that hive's agents, on the bridge | forwards to the swarm tier. Holds no credential, picks no destination |
|
||||
| | runs where | receives from | does |
|
||||
| ------------------------------------ | ---------------------- | --------------------------------- | ----------------------------------------------- |
|
||||
| **swarm tier** — `deploy.swarm-otel` | once per swarm | every hive's collector | writes the swarm's stores and exports upstream |
|
||||
| **hive tier** — `otel.enable` | every hive with agents | that hive's agents, on the bridge | forwards to the swarm tier. Holds no credential |
|
||||
|
||||
An all-local host runs both, and needs nothing said about the hop between them.
|
||||
An all-local host runs both; the hop between them configures itself.
|
||||
|
||||
```nix
|
||||
services.hyperhive.otel = {
|
||||
|
|
@ -31,7 +31,7 @@ services.hyperhive.otel = {
|
|||
## Enabling export
|
||||
|
||||
`otel.enable` is the single gate on a hive: one switch in the host config
|
||||
covers every agent container on it, with no per-agent opt-in or opt-out.
|
||||
covers every agent container on it.
|
||||
`endpoint` is where telemetry ends up after it leaves the swarm — optional,
|
||||
because the swarm's own metrics store (`deploy.victoriametrics`) is a
|
||||
destination in its own right. With both, telemetry goes to both. See
|
||||
|
|
@ -50,7 +50,7 @@ The hive collector reaches the swarm collector by its gateway name
|
|||
(`swarm.otel.domain`, default `otel.<swarm domain>`) — the same DNS-and-CA-trust
|
||||
shape every hive-to-swarm-service hop uses. On the host running the swarm
|
||||
collector the hive's dnsmasq answers that name; elsewhere it resolves through
|
||||
ordinary DNS. Nothing here needs setting for the split-host case.
|
||||
ordinary DNS.
|
||||
|
||||
⚠️ **The hive collector carries every bit of that hive's telemetry.** It
|
||||
runs on the same host as the agents and restarts on failure. Telemetry isn't
|
||||
|
|
@ -62,8 +62,7 @@ the control plane, so degraded telemetry isn't degraded operation.
|
|||
every agent needs the credential — and the only place to hand it to an agent
|
||||
container is somewhere the agent itself can read, its own claude settings
|
||||
among them. `0600` protects a secret from other containers, not from the
|
||||
agent it belongs to. An option that could select that path would reopen the
|
||||
hole.
|
||||
agent it belongs to.
|
||||
|
||||
**The tiers stay separate on one box.** An all-local hive is a statement about
|
||||
_where_ processes run, not about the shape of the deployment. A boundary that
|
||||
|
|
|
|||
Loading…
Reference in a new issue