diff --git a/nix/host-modules/swarm-otel.nix b/nix/host-modules/swarm-otel.nix index abf2231c..edb36ff5 100644 --- a/nix/host-modules/swarm-otel.nix +++ b/nix/host-modules/swarm-otel.nix @@ -202,18 +202,21 @@ let # because the receiver reads the path it is mounted at, and two spellings of # one path is a mount that succeeds and a receiver that finds nothing. # - # 🔑 Why the host's directory is enough to see every container — and why it - # is only enough because each container asks for it. nixpkgs hardcodes + # 🔑 Why the host's directory is enough to see a container — and why it is + # only enough because that container asks for it. nixpkgs hardcodes # `--link-journal=try-guest`, which puts the journal inside the container and # leaves the host with a symlink into that container's transient root: a # reader here cannot follow it, and it dangles the moment the container - # stops. Every container block therefore sets + # stops. Every container block except `swarm-bao` therefore sets # `extraFlags = [ "--link-journal=host" ]`, which the invocation expands # AFTER the hardcoded flag, so the files land here under their own # machine-id subdirectory and are bind-mounted into the guest instead. # - # ⚠️ Drop that flag from a container and this receiver silently stops seeing - # it — no error, just a unit that never appears in the store. + # ⚠️ Drop that flag from one of THOSE containers and this receiver silently + # stops seeing it — no error, just a unit that never appears in the store. + # `swarm-bao` is the one exception on purpose: its journal stays inside the + # container for its own collector instead (see `swarm-bao.nix`), so it was + # never one of the units this receiver could see either. hostJournalDir = "/var/log/journal"; # Each store's OTLP route, by domain. One binding because the same string is