module-eval: pin each swarm-bao reader's ordering after its policy unit
This commit is contained in:
parent
c92bb0dce7
commit
cde3fec956
1 changed files with 24 additions and 0 deletions
|
|
@ -438,6 +438,30 @@ let
|
||||||
&& !(baoGrantHere.containers.swarm-bao.config.systemd.services ? ${unit})
|
&& !(baoGrantHere.containers.swarm-bao.config.systemd.services ? ${unit})
|
||||||
) units;
|
) units;
|
||||||
}
|
}
|
||||||
|
{
|
||||||
|
# The other end of those units: each reader logs in against the role its
|
||||||
|
# own policy unit writes, so it has to wait for that unit. Ordering and
|
||||||
|
# never a requirement, since the policy unit skips once the token is gone.
|
||||||
|
name = "each of the four readers is ordered after the unit writing its role";
|
||||||
|
ok =
|
||||||
|
let
|
||||||
|
s = baoGrantWithConsumers.systemd.services;
|
||||||
|
waitsFor =
|
||||||
|
reader:
|
||||||
|
let
|
||||||
|
policy = "${reader}-policy.service";
|
||||||
|
in
|
||||||
|
lib.elem policy s.${reader}.after
|
||||||
|
&& lib.elem policy s.${reader}.wants
|
||||||
|
&& !(lib.elem policy s.${reader}.requires);
|
||||||
|
in
|
||||||
|
lib.all waitsFor [
|
||||||
|
"swarm-bao-matrix-token"
|
||||||
|
"swarm-bao-queue-agent"
|
||||||
|
"swarm-bao-grafana-oidc"
|
||||||
|
"swarm-bao-otel-oidc"
|
||||||
|
];
|
||||||
|
}
|
||||||
{
|
{
|
||||||
# A store host that has not placed a bootstrap token can write no grant at
|
# A store host that has not placed a bootstrap token can write no grant at
|
||||||
# all, so none of the four units may exist — the same claim
|
# all, so none of the four units may exist — the same claim
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue