diff --git a/nix/host-modules/default.nix b/nix/host-modules/default.nix index 0edf7691..dab30a4d 100644 --- a/nix/host-modules/default.nix +++ b/nix/host-modules/default.nix @@ -54,6 +54,7 @@ ./swarm-snapshot-store.nix ./swarm-ui.nix ./swarm-victorialogs.nix + ./swarm-victoriametrics-service.nix ./swarm-victoriametrics.nix ./swarm-wireguard.nix ./swarm.nix diff --git a/nix/host-modules/swarm-victoriametrics-service.nix b/nix/host-modules/swarm-victoriametrics-service.nix new file mode 100644 index 00000000..afa40511 --- /dev/null +++ b/nix/host-modules/swarm-victoriametrics-service.nix @@ -0,0 +1,57 @@ +# The swarm's metrics store as every hive sees it: the name it answers on and +# its port, identical on every host. What the host running it decides, and the +# container itself, are in ./swarm-victoriametrics.nix. +{ + lib, + config, + ... +}: +let + hyperhiveCfg = config.services.hyperhive; + swarmDomain = hyperhiveCfg.swarm.domain; + + # Total on a null swarm domain for the same reason every sibling module is: + # the required-domain assertion in hive-network.nix should be what an + # operator sees, not a coercion error from here. + domainBase = if swarmDomain == null then "invalid" else swarmDomain; +in +{ + # What the store IS from any hive's point of view: the name it answers on and + # the port. `enable`, `package` and `retentionPeriod` are decisions of the + # host that runs it and live under `deploy.*`. + options.services.hyperhive.swarm.victoriametrics = { + machine = lib.mkOption { + type = lib.types.str; + readOnly = true; + default = "swarm-victoriametrics"; + description = '' + Container name. Read-only: the name appears in host paths and in + `machinectl`, so it is a fact other modules may read rather than a + knob. + ''; + }; + + domain = lib.mkOption { + type = lib.types.str; + default = "metrics.${domainBase}"; + defaultText = lib.literalExpression ''"metrics.''${services.hyperhive.swarm.domain}"''; + description = '' + Name the gateway serves this on. A sibling of the swarm's other + service names, so the swarm-services sub-CA can issue for it — see + `hive-tls.nix` for why a service name being a sibling rather than a + child decides which CA may sign it. + ''; + }; + + port = lib.mkOption { + type = lib.types.port; + default = 8428; + description = '' + Port VictoriaMetrics listens on, bound to loopback only (see + below). Upstream's own default, kept so an operator reading + VictoriaMetrics documentation finds what they expect. + ''; + }; + + }; +} diff --git a/nix/host-modules/swarm-victoriametrics.nix b/nix/host-modules/swarm-victoriametrics.nix index 2b64a7ce..de8501db 100644 --- a/nix/host-modules/swarm-victoriametrics.nix +++ b/nix/host-modules/swarm-victoriametrics.nix @@ -21,57 +21,16 @@ let networkCfg = config.services.hyperhive.network; hyperhiveCfg = config.services.hyperhive; gatewayCfg = hyperhiveCfg.gateway; - swarmDomain = hyperhiveCfg.swarm.domain; - - # Total on a null swarm domain for the same reason every sibling module is: - # the required-domain assertion in hive-network.nix should be what an - # operator sees, not a coercion error from here. - domainBase = if swarmDomain == null then "invalid" else swarmDomain; # Shared host netns, like every sibling swarm container: the gateway # reaches this at 127.0.0.1:. privateNetwork = false; in { - # What stays here is what the store IS from any hive's point of view: the - # name it answers on and the port. `enable`, `package` and - # `retentionPeriod` are decisions of the host that runs it and live under - # `deploy.*`. - options.services.hyperhive.swarm.victoriametrics = { - machine = lib.mkOption { - type = lib.types.str; - readOnly = true; - default = "swarm-victoriametrics"; - description = '' - Container name. Read-only: the name appears in host paths and in - `machinectl`, so it is a fact other modules may read rather than a - knob. - ''; - }; - - domain = lib.mkOption { - type = lib.types.str; - default = "metrics.${domainBase}"; - defaultText = lib.literalExpression ''"metrics.''${services.hyperhive.swarm.domain}"''; - description = '' - Name the gateway serves this on. A sibling of the swarm's other - service names, so the swarm-services sub-CA can issue for it — see - `hive-tls.nix` for why a service name being a sibling rather than a - child decides which CA may sign it. - ''; - }; - - port = lib.mkOption { - type = lib.types.port; - default = 8428; - description = '' - Port VictoriaMetrics listens on, bound to loopback only (see - below). Upstream's own default, kept so an operator reading - VictoriaMetrics documentation finds what they expect. - ''; - }; - - }; + # What the store IS from any hive's point of view, the name it answers on and + # the port, is `swarm.victoriametrics` in ./swarm-victoriametrics-service.nix. + # `enable`, `package` and `retentionPeriod` are decisions of the host that + # runs it and live under `deploy.*`. # Retention is a property of the store this host runs, not something the # swarm has to agree on: it is read only where the container is defined,