Watch
0
0
Fork
You've already forked hyperhive
0

nix: split swarm-victorialogs into service and deploy-mode files

`swarm.victorialogs` (what the log store is to every hive: container name,
domain, port) moves to nix/host-modules/swarm-victorialogs-service.nix,
together with the only two helpers it reads, `swarmDomain` and
`domainBase`. Everything else -- the `deploy.victorialogs` options, the
whole `config` block including `containers.swarm-victorialogs`, the file
header and the helpers only they read (`swarmAuthRequest` among them) --
stays in nix/host-modules/swarm-victorialogs.nix, which default.nix now
imports alongside the new file.

`hyperhiveCfg` (an alias for `config.services.hyperhive`, not an option) is
read by both halves, so it is duplicated into the service file rather than
shared.

A pure move: option paths, option definitions and config are unchanged
apart from the comment above the `deploy.victorialogs` options, which now
names the file `swarm.victorialogs` lives in. Fixtures enabling the store
evaluate to the same host and container toplevel derivations before and
after.

Refs #3742
This commit is contained in:
atlas 2026-10-01 09:37:53 +02:00 • committed by mara
commit eef7b70c0e
3 changed files with 71 additions and 54 deletions

View file

@ -0,0 +1,66 @@
# The swarm's log store as every hive sees it: the name it answers on and its
# port, identical on every host. What the host running it decides, and the
# container itself, are in ./swarm-victorialogs.nix.
{
lib,
config,
...
}:
let
hyperhiveCfg = config.services.hyperhive;
swarmDomain = hyperhiveCfg.swarm.domain;
# Total on a null swarm domain for the same reason every sibling module is:
# the required-domain assertion in hive-network.nix should be what an
# operator sees, not a coercion error from here.
domainBase = if swarmDomain == null then "invalid" else swarmDomain;
in
{
# What the store IS from any hive's point of view: the name it answers on and
# the port. `enable`, `package` and `retentionPeriod` are decisions of the
# host that runs it and live under `deploy.*`.
options.services.hyperhive.swarm.victorialogs = {
machine = lib.mkOption {
type = lib.types.str;
readOnly = true;
default = "swarm-victorialogs";
description = ''
Container name. Read-only: the name appears in host paths and in
`machinectl`, so it is a fact other modules may read rather than a
knob.
'';
};
domain = lib.mkOption {
type = lib.types.str;
default = "logs.${domainBase}";
defaultText = lib.literalExpression ''"logs.''${services.hyperhive.swarm.domain}"'';
description = ''
Name the gateway serves this on, behind the same authelia
`auth_request` gate as the swarm UI's own vhost. A sibling of the
swarm's other service names, so the swarm-services sub-CA can
issue for it — see `hive-tls.nix` for why a service name being a
sibling rather than a child decides which CA may sign it, and
`swarm.nix`'s `serviceDomains'` for where this name has to be
registered for that to actually happen.
'';
};
port = lib.mkOption {
type = lib.types.port;
default = 9428;
description = ''
Loopback port the store listens on. Upstream's default, kept
because there is no reason to move it and a familiar number is
one less thing an operator has to look up.
⚠️ Every swarm container shares the host's network namespace, so
this is a swarm-wide claim rather than a per-container one — two
modules picking the same number collide at runtime with no bind
error and nothing in any log. `state/eval-port-collisions.sh`
checks the class.
'';
};
};
}