bao: mint the controller's leaf, and point the controller at it
glue-bao-tls.nix signs a third leaf. It is minted whether or not a controller runs here, because the case it serves is the one where it does not: a controller elsewhere needs a leaf from this CA and cannot sign one, so issuing it here turns "obtain a certificate out of band" into "copy this file". glue-controller-bao-identity.nix holds the pairing and nothing else -- which paths this host's controller reads. Gated on the leaf existing rather than on deploy.bao.enable, so a controller on the store's host and one three networks away with an out-of-band leaf get the same wiring; gating on the store would have made the co-located case the only supported shape. The directory comes from deploy.bao.clientCertFile rather than repeating glue-bao-tls.nix's literal, so moving the PKI moves both. module-eval gains three cases and two fixtures, because nothing asserted the PKI script before: an earlier commit added a leaf to that rendered unit and left the derivation unchanged. The fixture's CN is deliberately a value no default could supply, so "the role and the leaf both carry it" says they read one option rather than that both happen to say swarm-controller. Gates: 62 module properties hold (59 before, plus these three), on a derivation hash that actually moved -- this suite is a cache hit when only fixtures change, so an unchanged hash would have meant the cases never ran. nix fmt clean, all three scripts/check-*.sh exit 0.
This commit is contained in:
parent
a5dc62cecd
commit
c18aee8f74
4 changed files with 112 additions and 2 deletions
|
|
@ -24,6 +24,7 @@
|
|||
./hive-tls.nix
|
||||
./otel.nix
|
||||
./glue-bao-tls.nix
|
||||
./glue-controller-bao-identity.nix
|
||||
./glue-matrix-bao-token.nix
|
||||
./swarm-authelia.nix
|
||||
./swarm-bao.nix
|
||||
|
|
|
|||
Loading…
Reference in a new issue