docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
Follow-up to the plumbing removal: docs/swarm/README.md gets the biggest rewrite (drops the whole "Fingerprint format" section, fixes the runtime-effects list, the WireGuard config example + "what the mesh does" bullet), docs/gateway.md and hive-gateway/options.nix drop 4 "needs no certFingerprint" mentions, swarm-peers-removed.nix's migration-warning text no longer tells an upgrading operator to carry a field over that no longer exists, swarm.nix/swarm-wireguard.nix/ swarm-controller.nix/swarm-controller's main.rs get comment fixes where they described the now-removed HYPERHIVE_PEERS shape. Also caught one more stale "peer hives" mention in docs/web-ui/README.md's SW4RM tab description that the first pass on this issue missed.
This commit is contained in:
parent
c2f8ee225d
commit
c67100588e
8 changed files with 40 additions and 110 deletions
|
|
@ -48,7 +48,7 @@ in
|
|||
|
||||
services.hyperhive.swarm.hives.<name> = {
|
||||
domain = "<the old attrset key>";
|
||||
# certFingerprint / wireguard* carry over unchanged
|
||||
# wireguard* carries over unchanged
|
||||
};
|
||||
|
||||
Still set: ${lib.concatStringsSep ", " (lib.attrNames peers)}
|
||||
|
|
@ -61,9 +61,7 @@ in
|
|||
(services.hyperhive.swarm.ca — see docs/swarm/ca.md): every hive
|
||||
under it chains to it, so a per-hive CA is dead weight. What this
|
||||
genuinely drops is trusting a hive whose root this swarm does NOT
|
||||
own — another swarm's, or one keeping its own CA. certFingerprint
|
||||
does not cover that: it pins a leaf for hive-c0re's own HTTPS
|
||||
checks and does not reach Matrix federation.
|
||||
own — another swarm's, or one keeping its own CA.
|
||||
|
||||
Still set on: ${lib.concatStringsSep ", " withCaCert}
|
||||
'';
|
||||
|
|
|
|||
Loading…
Reference in a new issue