swarm-otel: correct the hostJournalDir comment for swarm-bao's exception

argus review on #4713: the comment said every container block sets
--link-journal=host, and warned that dropping it silently blinds this
receiver. #4713 does exactly that for swarm-bao (its journal stays
inside the container for its own collector instead), so read on its
own the comment told a debugger to revert the fix. State the
exception.
This commit is contained in:
atlas 2026-09-24 23:44:32 +02:00
commit c4edb78aa2

View file

@ -202,18 +202,21 @@ let
# because the receiver reads the path it is mounted at, and two spellings of
# one path is a mount that succeeds and a receiver that finds nothing.
#
# 🔑 Why the host's directory is enough to see every container — and why it
# is only enough because each container asks for it. nixpkgs hardcodes
# 🔑 Why the host's directory is enough to see a container — and why it is
# only enough because that container asks for it. nixpkgs hardcodes
# `--link-journal=try-guest`, which puts the journal inside the container and
# leaves the host with a symlink into that container's transient root: a
# reader here cannot follow it, and it dangles the moment the container
# stops. Every container block therefore sets
# stops. Every container block except `swarm-bao` therefore sets
# `extraFlags = [ "--link-journal=host" ]`, which the invocation expands
# AFTER the hardcoded flag, so the files land here under their own
# machine-id subdirectory and are bind-mounted into the guest instead.
#
# ⚠️ Drop that flag from a container and this receiver silently stops seeing
# it — no error, just a unit that never appears in the store.
# ⚠️ Drop that flag from one of THOSE containers and this receiver silently
# stops seeing it — no error, just a unit that never appears in the store.
# `swarm-bao` is the one exception on purpose: its journal stays inside the
# container for its own collector instead (see `swarm-bao.nix`), so it was
# never one of the units this receiver could see either.
hostJournalDir = "/var/log/journal";
# Each store's OTLP route, by domain. One binding because the same string is