swarm-bao: stamp collector's service.name as "bao"

bao's own in-container collector labelled every log line and metric it
forwards `service.name=swarm-bao` (`processors.resource.attributes`,
keyed off `swarm.bao.machine`), while every panel in the shipped
Grafana bao dashboard queries the literal `service.name="bao"` — no
panel has matched since the scrape moved into that collector.

Rename it in the collector instead of templating the dashboard: a new
`collectorServiceName` binding in swarm-bao.nix, deliberately not
`cfg.machine` (that value names the container/receiver, not bao's
display identity), stamps `service.name="bao"` directly. bao.json is
back to its origin/main shape, unchanged.

Adds a module-eval case to checks.module-eval-grafana that reads the
collector's own evaluated config and asserts its service.name matches
every selector the shipped dashboard uses; verified invert-proof by
setting the value back to cfg.machine and confirming that specific
case (and only it) fails.
This commit is contained in:
atlas 2026-09-24 21:37:58 +02:00 • committed by mara
commit cb176c7be7
2 changed files with 53 additions and 1 deletions

View file

@ -41,6 +41,17 @@ let
networkCfg = hyperhiveCfg.network;
swarmDomain = hyperhiveCfg.swarm.domain;
# What this container's own collector stamps as `service.name` on every
# log line and metric it forwards, and the value the shipped Grafana
# dashboard's (`swarm-grafana/dashboards/bao.json`) panels all select on.
# Deliberately NOT `cfg.machine`: that value names the *container* — it is
# also the swarm-tier receiver/authenticator component name
# (`otlp/${cfg.machine}` in ./swarm-otel.nix) and could change for reasons
# that have nothing to do with what the dashboard queries. One literal,
# bound once, so the collector and the dashboard can't drift apart —
# `nix/module-eval/grafana.nix` pins it against the shipped dashboard file.
collectorServiceName = "bao";
# Upstream's own default, kept so its documentation matches. The raft data
# lives INSIDE the container on `ephemeral = false`, the same way
# ./swarm-grafana.nix keeps its sqlite database — no sibling service binds
@ -2782,10 +2793,14 @@ in
# `hive` or `swarm` label — the swarm tier upserts `hive` from
# the receiver that accepted the record, precisely so it comes
# from something the sender cannot write.
#
# `collectorServiceName`, not `cfg.machine`: what the
# dashboard selects on is a display identity, not the
# container/receiver name — see that binding's own comment.
processors.resource.attributes = [
{
key = "service.name";
value = cfg.machine;
value = collectorServiceName;
action = "upsert";
}
];