isolation: forward HIVE_MATRIX_URL so matrix daemon reaches the gateway

This commit is contained in:
damocles 2026-06-15 21:38:34 +02:00
commit d15ecff6d2
3 changed files with 32 additions and 1 deletions

View file

@ -505,6 +505,7 @@ const CANONICAL_INPUTS: &[&str] = &["nixpkgs", "nixpkgs-unstable"];
const FORWARDED_VARS: &[&str] = &[
"HIVE_FORGE_URL",
"HIVE_FORGE_PUBLIC_URL",
"HIVE_MATRIX_URL",
"HYPERHIVE_PEERS",
"HYPERHIVE_HIVE_DOMAIN",
"HYPERHIVE_HIVE_NAME",

View file

@ -764,6 +764,26 @@ in
else
"http://127.0.0.1:${toString config.services.hyperhive.forge.httpPort}";
}
// lib.optionalAttrs config.services.hyperhive.matrix.enable {
# In-cluster matrix homeserver URL for each agent's
# hive-matrix-daemon. Same shape + rationale as HIVE_FORGE_URL:
# - Isolated (private netns): reach tuwunel via the gateway vhost
# (`matrix.<domain>`) on plain http:80 — host loopback is dead.
# - Shared netns: direct host loopback on the tuwunel port.
# gatewayHost null-guard falls back to loopback so a domain-less
# config doesn't break eval (it just won't work under isolation,
# which needs a gateway anyway). Forwarded to agents by meta.rs
# alongside HIVE_FORGE_URL; shares the #1693 ordering caveat.
HIVE_MATRIX_URL =
if
config.services.hyperhive.network.enable
&& config.services.hyperhive.network.isolateContainers
&& config.services.hyperhive.matrix.gatewayHost != null
then
"http://${config.services.hyperhive.matrix.gatewayHost}"
else
"http://127.0.0.1:${toString config.services.hyperhive.matrix.httpPort}";
}
// lib.optionalAttrs config.services.hyperhive.matrix.gui.enable {
# Availability flags read by the dashboard's `/api/state`.
# Matrix GUI lives entirely on the gateway nginx (matrix tab

View file

@ -1327,10 +1327,20 @@ in
after = [ "network-online.target" ];
wants = [ "network-online.target" ];
environment = {
HIVE_MATRIX_URL = config.hyperhive.matrix.url;
HIVE_MATRIX_SOCKET = "/run/hive-matrix/socket";
RUST_LOG = "info";
}
# Homeserver URL: by default the daemon inherits the host-forwarded
# HIVE_MATRIX_URL (set isolation-aware by hive-c0re: `matrix.<domain>`
# via the gateway under private-netns isolation, loopback otherwise),
# falling back to the daemon's built-in localhost default if the
# forward is absent. A per-agent `hyperhive.matrix.url` override
# (non-default) is set unit-level so it wins over the forwarded value;
# at the default we deliberately DON'T set it so the forwarded
# isolation-aware value isn't shadowed.
// lib.optionalAttrs (config.hyperhive.matrix.url != "http://localhost:8008") {
HIVE_MATRIX_URL = config.hyperhive.matrix.url;
}
# Multi-account: serialize the *extra* accounts to the JSON the
# daemon parses (`accounts::configured`). Only set when extras are
# declared; the daemon always synthesizes the primary `main`