diff --git a/nix/host-modules/glue-matrix-bao-token.nix b/nix/host-modules/glue-matrix-bao-token.nix index 3c0afcb6..07c429ce 100644 --- a/nix/host-modules/glue-matrix-bao-token.nix +++ b/nix/host-modules/glue-matrix-bao-token.nix @@ -136,11 +136,19 @@ in # `Requires=` on an absent unit fails the job outright, so the ordering is # conditional even though the read is not: off-host there is nothing local # to wait for, and the timeout below is what bounds the attempt instead. + # + # The policy unit writes the role this reader logs in with. Ordering + # only: it skips once the bootstrap token is gone, and a skipped unit + # counts as done. after = lib.optionals baoDeploy.enable [ "swarm-bao-pki.service" "container@${baoCfg.machine}.service" + "swarm-bao-matrix-token-policy.service" + ]; + wants = lib.optionals baoDeploy.enable [ + "container@${baoCfg.machine}.service" + "swarm-bao-matrix-token-policy.service" ]; - wants = lib.optionals baoDeploy.enable [ "container@${baoCfg.machine}.service" ]; requires = lib.optionals baoDeploy.enable [ "swarm-bao-pki.service" ]; before = [ "container@${matrixMachine}.service" ]; wantedBy = [ "container@${matrixMachine}.service" ]; diff --git a/nix/host-modules/glue-queue-agent-credential.nix b/nix/host-modules/glue-queue-agent-credential.nix index 8fa2dc06..e2894e35 100644 --- a/nix/host-modules/glue-queue-agent-credential.nix +++ b/nix/host-modules/glue-queue-agent-credential.nix @@ -161,11 +161,19 @@ in # `Requires=` on an absent unit fails the job outright, so the ordering is # conditional even though the read is not: off-host there is nothing local # to wait for, and the timeout below is what bounds the attempt instead. + # + # The policy unit writes the role this reader logs in with. Ordering + # only: it skips once the bootstrap token is gone, and a skipped unit + # counts as done. after = lib.optionals baoDeploy.enable [ "swarm-bao-pki.service" "container@${baoCfg.machine}.service" + "swarm-bao-queue-agent-policy.service" + ]; + wants = lib.optionals baoDeploy.enable [ + "container@${baoCfg.machine}.service" + "swarm-bao-queue-agent-policy.service" ]; - wants = lib.optionals baoDeploy.enable [ "container@${baoCfg.machine}.service" ]; requires = lib.optionals baoDeploy.enable [ "swarm-bao-pki.service" ]; # Ordered before hive-c0re, so no agent container renders ahead of an # attempt at its credential. `Wants=`, not `Requires=`: a store this diff --git a/nix/host-modules/swarm-grafana.nix b/nix/host-modules/swarm-grafana.nix index 85e5a2d1..1ebac1f3 100644 --- a/nix/host-modules/swarm-grafana.nix +++ b/nix/host-modules/swarm-grafana.nix @@ -583,11 +583,19 @@ in # `Requires=` on an absent unit fails the job outright, so the ordering # is conditional even though the read is not: off-host there is nothing # local to wait for, and the timeout below bounds the attempt instead. + # + # The policy unit writes the role this reader logs in with. Ordering + # only: it skips once the bootstrap token is gone, and a skipped unit + # counts as done. after = lib.optionals baoDeploy.enable [ "swarm-bao-pki.service" "container@${baoCfg.machine}.service" + "swarm-bao-grafana-oidc-policy.service" + ]; + wants = lib.optionals baoDeploy.enable [ + "container@${baoCfg.machine}.service" + "swarm-bao-grafana-oidc-policy.service" ]; - wants = lib.optionals baoDeploy.enable [ "container@${baoCfg.machine}.service" ]; requires = lib.optionals baoDeploy.enable [ "swarm-bao-pki.service" ]; before = [ "container@${cfg.machine}.service" ]; wantedBy = [ diff --git a/nix/host-modules/swarm-otel.nix b/nix/host-modules/swarm-otel.nix index 0b5cc904..51605ba8 100644 --- a/nix/host-modules/swarm-otel.nix +++ b/nix/host-modules/swarm-otel.nix @@ -766,11 +766,19 @@ in # `Requires=` on an absent unit fails the job outright, so the ordering # is conditional even though the read is not: off-host there is nothing # local to wait for, and the timeout below bounds the attempt instead. + # + # The policy unit writes the role this reader logs in with. Ordering + # only: it skips once the bootstrap token is gone, and a skipped unit + # counts as done. after = lib.optionals baoDeploy.enable [ "swarm-bao-pki.service" "container@${baoCfg.machine}.service" + "swarm-bao-otel-oidc-policy.service" + ]; + wants = lib.optionals baoDeploy.enable [ + "container@${baoCfg.machine}.service" + "swarm-bao-otel-oidc-policy.service" ]; - wants = lib.optionals baoDeploy.enable [ "container@${baoCfg.machine}.service" ]; requires = lib.optionals baoDeploy.enable [ "swarm-bao-pki.service" ]; before = [ "container@${cfg.machine}.service" ]; wantedBy = [