module-eval: pin each swarm-bao reader's ordering after its policy unit
This commit is contained in:
parent
c92bb0dce7
commit
cde3fec956
1 changed files with 24 additions and 0 deletions
|
|
@ -438,6 +438,30 @@ let
|
|||
&& !(baoGrantHere.containers.swarm-bao.config.systemd.services ? ${unit})
|
||||
) units;
|
||||
}
|
||||
{
|
||||
# The other end of those units: each reader logs in against the role its
|
||||
# own policy unit writes, so it has to wait for that unit. Ordering and
|
||||
# never a requirement, since the policy unit skips once the token is gone.
|
||||
name = "each of the four readers is ordered after the unit writing its role";
|
||||
ok =
|
||||
let
|
||||
s = baoGrantWithConsumers.systemd.services;
|
||||
waitsFor =
|
||||
reader:
|
||||
let
|
||||
policy = "${reader}-policy.service";
|
||||
in
|
||||
lib.elem policy s.${reader}.after
|
||||
&& lib.elem policy s.${reader}.wants
|
||||
&& !(lib.elem policy s.${reader}.requires);
|
||||
in
|
||||
lib.all waitsFor [
|
||||
"swarm-bao-matrix-token"
|
||||
"swarm-bao-queue-agent"
|
||||
"swarm-bao-grafana-oidc"
|
||||
"swarm-bao-otel-oidc"
|
||||
];
|
||||
}
|
||||
{
|
||||
# A store host that has not placed a bootstrap token can write no grant at
|
||||
# all, so none of the four units may exist — the same claim
|
||||
|
|
|
|||
Loading…
Reference in a new issue