diff --git a/nix/host-modules/swarm-authelia.nix b/nix/host-modules/swarm-authelia.nix index 38aac164..027d9667 100644 --- a/nix/host-modules/swarm-authelia.nix +++ b/nix/host-modules/swarm-authelia.nix @@ -99,7 +99,7 @@ let unitName = "authelia-${instance}"; stateDir = "/var/lib/${unitName}"; - tlsCfg = hyperhiveCfg.tls; + tlsCfg = deployCfg.hive-controller.tls; caTrust = import ./lib/hive-ca-trust.nix { inherit lib tlsCfg gatewayCfg; }; # `swarm-authelia-bridge` verifies the gateway when it introspects by name. # Nothing in this container trusted the swarm CA, which is a runtime file no diff --git a/nix/host-modules/swarm-grafana.nix b/nix/host-modules/swarm-grafana.nix index 81ec4374..df6f45f6 100644 --- a/nix/host-modules/swarm-grafana.nix +++ b/nix/host-modules/swarm-grafana.nix @@ -20,7 +20,7 @@ let networkCfg = config.services.hyperhive.network; hyperhiveCfg = config.services.hyperhive; gatewayCfg = hyperhiveCfg.gateway; - tlsCfg = hyperhiveCfg.tls; + tlsCfg = deployCfg.hive-controller.tls; autheliaCfg = hyperhiveCfg.swarm.authelia; vmCfg = hyperhiveCfg.swarm.victoriametrics; vlCfg = hyperhiveCfg.swarm.victorialogs; diff --git a/nix/host-modules/swarm-otel.nix b/nix/host-modules/swarm-otel.nix index 5856b39f..01ed5c58 100644 --- a/nix/host-modules/swarm-otel.nix +++ b/nix/host-modules/swarm-otel.nix @@ -163,7 +163,7 @@ let # `security.pki.certificateFiles`. caTrust = import ./lib/hive-ca-trust.nix { inherit lib; - tlsCfg = hyperhiveCfg.tls; + tlsCfg = deployCfg.hive-controller.tls; inherit gatewayCfg; };