nix: order each swarm-bao secret reader after the policy unit writing its role
The four readers (matrix-token, queue-agent, grafana-oidc, otel-oidc) log in against a cert-auth role that their own swarm-bao-*-policy unit writes. They were ordered after swarm-bao-pki and the store's container but not after that unit, so on an apply a reader could log in before its role existed and be refused by `allowed_common_names` until a retry landed after the role did. After= plus Wants= on the policy unit, never Requires=: the policy unit skips by ConditionPathExists once the bootstrap token is gone, and a skipped unit counts as done for ordering.
This commit is contained in:
parent
aa719da571
commit
c92bb0dce7
4 changed files with 36 additions and 4 deletions
|
|
@ -583,11 +583,19 @@ in
|
|||
# `Requires=` on an absent unit fails the job outright, so the ordering
|
||||
# is conditional even though the read is not: off-host there is nothing
|
||||
# local to wait for, and the timeout below bounds the attempt instead.
|
||||
#
|
||||
# The policy unit writes the role this reader logs in with. Ordering
|
||||
# only: it skips once the bootstrap token is gone, and a skipped unit
|
||||
# counts as done.
|
||||
after = lib.optionals baoDeploy.enable [
|
||||
"swarm-bao-pki.service"
|
||||
"container@${baoCfg.machine}.service"
|
||||
"swarm-bao-grafana-oidc-policy.service"
|
||||
];
|
||||
wants = lib.optionals baoDeploy.enable [
|
||||
"container@${baoCfg.machine}.service"
|
||||
"swarm-bao-grafana-oidc-policy.service"
|
||||
];
|
||||
wants = lib.optionals baoDeploy.enable [ "container@${baoCfg.machine}.service" ];
|
||||
requires = lib.optionals baoDeploy.enable [ "swarm-bao-pki.service" ];
|
||||
before = [ "container@${cfg.machine}.service" ];
|
||||
wantedBy = [
|
||||
|
|
|
|||
Loading…
Reference in a new issue