docs/gateway.md: extract hive-c0re + hive-forge prose blocks (#718 batch 2)
Continues #718 docs-extraction. Three more blocks moved to `docs/gateway.md` (which already houses the gateway architecture story from #775): 1. **Firewall posture (gateway on vs off)** — was a 22-line block above `networking.firewall = lib.mkIf ...` in hive-c0re.nix. Trimmed to 3-line ref. New `docs/gateway.md::Firewall posture (host-level)` section covers the gateway-on / gateway-off trade-off + why dashboard port stays loopback-only. 2. **`HIVE_FORGE_URL` loopback rationale** — was a 14-line block above the env-var assignment. Trimmed to 5-line ref. New `docs/gateway.md::HIVE_FORGE_URL: loopback for in-cluster, sub-domain for the operator` section covers the in-cluster vs external split + why agent containers can't use the sub-domain. 3. **hive-forge container shape** — was a 15-line top-of-`config` block in hive-forge.nix explaining the nixos-container + host netns choices. Trimmed to 4-line ref. New `docs/gateway.md::hive-forge container shape` section captures the same content with state-dir + wipe-via-destroy notes. Net: hive-c0re.nix -29 lines, hive-forge.nix -11 lines, gateway.md +44 lines. Same pattern as #782 (first pass) per iris's #10114 guidance — substantive WHY moves to docs as named sub-paragraphs, in-code shrinks to `// see docs/<file>::<section>` refs. Verified: `nix eval` on agent-base toplevel still resolves cleanly; firewall posture unchanged (still 0 ports opened in the gateway-on case + the same 8100..8999 range in the gateway-off case). Continues #718. Follow-up batches: remaining harness-base.nix blocks, nix/docs/default.nix, nix/assets.nix, nix/templates/weston-vnc.nix.
This commit is contained in:
parent
df71d8deac
commit
ea90814809
3 changed files with 63 additions and 51 deletions
|
|
@ -30,21 +30,10 @@ let
|
|||
effectiveRootUrl = if cfg.rootUrl != null then cfg.rootUrl else defaultRootUrl;
|
||||
in
|
||||
{
|
||||
# Private Forgejo for hyperhive agents, wrapped in a nixos-container
|
||||
# so it doesn't fight any `services.forgejo` the operator already
|
||||
# runs on the host. The container shares the host network namespace
|
||||
# (`privateNetwork = false`) so agents reach the forge at
|
||||
# `http://localhost:<httpPort>` without any extra plumbing —
|
||||
# nixos-container is just here for state + systemd-unit isolation,
|
||||
# not network isolation.
|
||||
#
|
||||
# Container name is `hive-forge` (not `h-*`), so hive-c0re's
|
||||
# lifecycle scanner ignores it; the operator manages it via the
|
||||
# standard `nixos-container` CLI.
|
||||
#
|
||||
# State lives at `/var/lib/nixos-containers/hive-forge/var/lib/forgejo/`
|
||||
# and survives container restart / host reboot. To wipe, destroy the
|
||||
# container.
|
||||
# Private Forgejo in a `hive-forge` nixos-container, shared host
|
||||
# netns so agents reach it on loopback. State at
|
||||
# `/var/lib/nixos-containers/hive-forge/var/lib/forgejo/` survives
|
||||
# restart. See `docs/gateway.md::hive-forge container shape`.
|
||||
|
||||
options.services.hyperhive.forge = {
|
||||
enable = lib.mkOption {
|
||||
|
|
|
|||
Loading…
Reference in a new issue