nix: order each swarm-bao secret reader after the policy unit writing its role

The four readers (matrix-token, queue-agent, grafana-oidc, otel-oidc) log
in against a cert-auth role that their own swarm-bao-*-policy unit writes.
They were ordered after swarm-bao-pki and the store's container but not
after that unit, so on an apply a reader could log in before its role
existed and be refused by `allowed_common_names` until a retry landed
after the role did.

After= plus Wants= on the policy unit, never Requires=: the policy unit
skips by ConditionPathExists once the bootstrap token is gone, and a
skipped unit counts as done for ordering.
This commit is contained in:
atlas 2026-09-24 13:07:18 +02:00 • committed by mara
commit c92bb0dce7
4 changed files with 36 additions and 4 deletions

View file

@ -583,11 +583,19 @@ in
# `Requires=` on an absent unit fails the job outright, so the ordering
# is conditional even though the read is not: off-host there is nothing
# local to wait for, and the timeout below bounds the attempt instead.
#
# The policy unit writes the role this reader logs in with. Ordering
# only: it skips once the bootstrap token is gone, and a skipped unit
# counts as done.
after = lib.optionals baoDeploy.enable [
"swarm-bao-pki.service"
"container@${baoCfg.machine}.service"
"swarm-bao-grafana-oidc-policy.service"
];
wants = lib.optionals baoDeploy.enable [
"container@${baoCfg.machine}.service"
"swarm-bao-grafana-oidc-policy.service"
];
wants = lib.optionals baoDeploy.enable [ "container@${baoCfg.machine}.service" ];
requires = lib.optionals baoDeploy.enable [ "swarm-bao-pki.service" ];
before = [ "container@${cfg.machine}.service" ];
wantedBy = [