module-eval: pin each swarm-bao reader's ordering after its policy unit

This commit is contained in:
atlas 2026-09-24 13:08:40 +02:00 • committed by mara
commit cde3fec956

View file

@ -438,6 +438,30 @@ let
&& !(baoGrantHere.containers.swarm-bao.config.systemd.services ? ${unit}) && !(baoGrantHere.containers.swarm-bao.config.systemd.services ? ${unit})
) units; ) units;
} }
{
# The other end of those units: each reader logs in against the role its
# own policy unit writes, so it has to wait for that unit. Ordering and
# never a requirement, since the policy unit skips once the token is gone.
name = "each of the four readers is ordered after the unit writing its role";
ok =
let
s = baoGrantWithConsumers.systemd.services;
waitsFor =
reader:
let
policy = "${reader}-policy.service";
in
lib.elem policy s.${reader}.after
&& lib.elem policy s.${reader}.wants
&& !(lib.elem policy s.${reader}.requires);
in
lib.all waitsFor [
"swarm-bao-matrix-token"
"swarm-bao-queue-agent"
"swarm-bao-grafana-oidc"
"swarm-bao-otel-oidc"
];
}
{ {
# A store host that has not placed a bootstrap token can write no grant at # A store host that has not placed a bootstrap token can write no grant at
# all, so none of the four units may exist — the same claim # all, so none of the four units may exist — the same claim