diff --git a/nix/module-eval/bao-grants.nix b/nix/module-eval/bao-grants.nix index 0d4075dd..1633c2ea 100644 --- a/nix/module-eval/bao-grants.nix +++ b/nix/module-eval/bao-grants.nix @@ -438,6 +438,30 @@ let && !(baoGrantHere.containers.swarm-bao.config.systemd.services ? ${unit}) ) units; } + { + # The other end of those units: each reader logs in against the role its + # own policy unit writes, so it has to wait for that unit. Ordering and + # never a requirement, since the policy unit skips once the token is gone. + name = "each of the four readers is ordered after the unit writing its role"; + ok = + let + s = baoGrantWithConsumers.systemd.services; + waitsFor = + reader: + let + policy = "${reader}-policy.service"; + in + lib.elem policy s.${reader}.after + && lib.elem policy s.${reader}.wants + && !(lib.elem policy s.${reader}.requires); + in + lib.all waitsFor [ + "swarm-bao-matrix-token" + "swarm-bao-queue-agent" + "swarm-bao-grafana-oidc" + "swarm-bao-otel-oidc" + ]; + } { # A store host that has not placed a bootstrap token can write no grant at # all, so none of the four units may exist — the same claim