nix: split swarm-authelia into service and deploy-mode files
`swarm.authelia` (what the SSO provider is to every hive: ports, domain, `url`, the OIDC client register, the published names and the bridge's address) moves to nix/host-modules/swarm-authelia-service.nix. Everything else -- the `deploy.authelia` options, the whole `config` block including `containers.swarm-authelia`, and the helpers only they read -- stays in nix/host-modules/swarm-authelia.nix, which default.nix now imports alongside the new file. Both halves read four `let` bindings. `cfg`, `swarmDomain` and `deployCfg` are option reads, so each file binds them from `config`; the service file has no `hyperhiveCfg`, so it spells the paths out, as swarm-nats-service.nix does. `instance` and `unitName` are literals, not options, so the service file carries its own copy of the two (`unit`'s default reads `unitName`). `deployCfg` is in the service file only for `bridgeUrl`'s default, which is moved as it is. `hyperhiveDomain` had no reader and is dropped rather than carried into either file. A pure move: option paths, option definitions and config are unchanged apart from three comments that pointed "above"/"below" across the new file boundary and now name the file. Authelia's container toplevel, the host toplevel (with `c0re.hyperhiveFlake` pinned, since the flake source path lands in /etc/hyperhive/serve.json), the `swarm.authelia` and `deploy.authelia` values and option set, and the eleven module-eval checks that enable authelia evaluate to the same derivations before and after. Refs #3742
This commit is contained in:
parent
eef7b70c0e
commit
ba56bfe32e
3 changed files with 476 additions and 453 deletions
|
|
@ -40,6 +40,7 @@
|
|||
./glue-services-issuer-bao-identity.nix
|
||||
./glue-swarm-bao-otel-oidc-client.nix
|
||||
./glue-swarm-otel-oidc-client.nix
|
||||
./swarm-authelia-service.nix
|
||||
./swarm-authelia.nix
|
||||
./swarm-bao-service.nix
|
||||
./swarm-bao.nix
|
||||
|
|
|
|||
Loading…
Reference in a new issue