nix: split swarm-victoriametrics into service and deploy-mode files
`swarm.victoriametrics` (what the metrics store is to every hive: container name, domain, port) moves to nix/host-modules/swarm-victoriametrics-service.nix, together with the only two helpers it reads, `swarmDomain` and `domainBase`. Everything else -- the `deploy.victoriametrics` options, the whole `config` block including `containers.swarm-victoriametrics`, the file header and the helpers only they read -- stays in nix/host-modules/swarm-victoriametrics.nix, which default.nix now imports alongside the new file. `hyperhiveCfg` (an alias for `config.services.hyperhive`, not an option) is read by both halves, so it is duplicated into the service file rather than shared. A pure move: option paths, option definitions and config are unchanged apart from the comment above the `deploy.victoriametrics` options, which now names the file `swarm.victoriametrics` lives in. Fixtures enabling the store evaluate to the same host and container toplevel derivations before and after. Refs #3742
This commit is contained in:
parent
9a815e9658
commit
f18d8099f5
3 changed files with 62 additions and 45 deletions
|
|
@ -54,6 +54,7 @@
|
||||||
./swarm-snapshot-store.nix
|
./swarm-snapshot-store.nix
|
||||||
./swarm-ui.nix
|
./swarm-ui.nix
|
||||||
./swarm-victorialogs.nix
|
./swarm-victorialogs.nix
|
||||||
|
./swarm-victoriametrics-service.nix
|
||||||
./swarm-victoriametrics.nix
|
./swarm-victoriametrics.nix
|
||||||
./swarm-wireguard.nix
|
./swarm-wireguard.nix
|
||||||
./swarm.nix
|
./swarm.nix
|
||||||
|
|
|
||||||
57
nix/host-modules/swarm-victoriametrics-service.nix
Normal file
57
nix/host-modules/swarm-victoriametrics-service.nix
Normal file
|
|
@ -0,0 +1,57 @@
|
||||||
|
# The swarm's metrics store as every hive sees it: the name it answers on and
|
||||||
|
# its port, identical on every host. What the host running it decides, and the
|
||||||
|
# container itself, are in ./swarm-victoriametrics.nix.
|
||||||
|
{
|
||||||
|
lib,
|
||||||
|
config,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
let
|
||||||
|
hyperhiveCfg = config.services.hyperhive;
|
||||||
|
swarmDomain = hyperhiveCfg.swarm.domain;
|
||||||
|
|
||||||
|
# Total on a null swarm domain for the same reason every sibling module is:
|
||||||
|
# the required-domain assertion in hive-network.nix should be what an
|
||||||
|
# operator sees, not a coercion error from here.
|
||||||
|
domainBase = if swarmDomain == null then "invalid" else swarmDomain;
|
||||||
|
in
|
||||||
|
{
|
||||||
|
# What the store IS from any hive's point of view: the name it answers on and
|
||||||
|
# the port. `enable`, `package` and `retentionPeriod` are decisions of the
|
||||||
|
# host that runs it and live under `deploy.*`.
|
||||||
|
options.services.hyperhive.swarm.victoriametrics = {
|
||||||
|
machine = lib.mkOption {
|
||||||
|
type = lib.types.str;
|
||||||
|
readOnly = true;
|
||||||
|
default = "swarm-victoriametrics";
|
||||||
|
description = ''
|
||||||
|
Container name. Read-only: the name appears in host paths and in
|
||||||
|
`machinectl`, so it is a fact other modules may read rather than a
|
||||||
|
knob.
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
|
||||||
|
domain = lib.mkOption {
|
||||||
|
type = lib.types.str;
|
||||||
|
default = "metrics.${domainBase}";
|
||||||
|
defaultText = lib.literalExpression ''"metrics.''${services.hyperhive.swarm.domain}"'';
|
||||||
|
description = ''
|
||||||
|
Name the gateway serves this on. A sibling of the swarm's other
|
||||||
|
service names, so the swarm-services sub-CA can issue for it — see
|
||||||
|
`hive-tls.nix` for why a service name being a sibling rather than a
|
||||||
|
child decides which CA may sign it.
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
|
||||||
|
port = lib.mkOption {
|
||||||
|
type = lib.types.port;
|
||||||
|
default = 8428;
|
||||||
|
description = ''
|
||||||
|
Port VictoriaMetrics listens on, bound to loopback only (see
|
||||||
|
below). Upstream's own default, kept so an operator reading
|
||||||
|
VictoriaMetrics documentation finds what they expect.
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
@ -21,57 +21,16 @@ let
|
||||||
networkCfg = config.services.hyperhive.network;
|
networkCfg = config.services.hyperhive.network;
|
||||||
hyperhiveCfg = config.services.hyperhive;
|
hyperhiveCfg = config.services.hyperhive;
|
||||||
gatewayCfg = hyperhiveCfg.gateway;
|
gatewayCfg = hyperhiveCfg.gateway;
|
||||||
swarmDomain = hyperhiveCfg.swarm.domain;
|
|
||||||
|
|
||||||
# Total on a null swarm domain for the same reason every sibling module is:
|
|
||||||
# the required-domain assertion in hive-network.nix should be what an
|
|
||||||
# operator sees, not a coercion error from here.
|
|
||||||
domainBase = if swarmDomain == null then "invalid" else swarmDomain;
|
|
||||||
|
|
||||||
# Shared host netns, like every sibling swarm container: the gateway
|
# Shared host netns, like every sibling swarm container: the gateway
|
||||||
# reaches this at 127.0.0.1:<port>.
|
# reaches this at 127.0.0.1:<port>.
|
||||||
privateNetwork = false;
|
privateNetwork = false;
|
||||||
in
|
in
|
||||||
{
|
{
|
||||||
# What stays here is what the store IS from any hive's point of view: the
|
# What the store IS from any hive's point of view, the name it answers on and
|
||||||
# name it answers on and the port. `enable`, `package` and
|
# the port, is `swarm.victoriametrics` in ./swarm-victoriametrics-service.nix.
|
||||||
# `retentionPeriod` are decisions of the host that runs it and live under
|
# `enable`, `package` and `retentionPeriod` are decisions of the host that
|
||||||
# `deploy.*`.
|
# runs it and live under `deploy.*`.
|
||||||
options.services.hyperhive.swarm.victoriametrics = {
|
|
||||||
machine = lib.mkOption {
|
|
||||||
type = lib.types.str;
|
|
||||||
readOnly = true;
|
|
||||||
default = "swarm-victoriametrics";
|
|
||||||
description = ''
|
|
||||||
Container name. Read-only: the name appears in host paths and in
|
|
||||||
`machinectl`, so it is a fact other modules may read rather than a
|
|
||||||
knob.
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
|
|
||||||
domain = lib.mkOption {
|
|
||||||
type = lib.types.str;
|
|
||||||
default = "metrics.${domainBase}";
|
|
||||||
defaultText = lib.literalExpression ''"metrics.''${services.hyperhive.swarm.domain}"'';
|
|
||||||
description = ''
|
|
||||||
Name the gateway serves this on. A sibling of the swarm's other
|
|
||||||
service names, so the swarm-services sub-CA can issue for it — see
|
|
||||||
`hive-tls.nix` for why a service name being a sibling rather than a
|
|
||||||
child decides which CA may sign it.
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
|
|
||||||
port = lib.mkOption {
|
|
||||||
type = lib.types.port;
|
|
||||||
default = 8428;
|
|
||||||
description = ''
|
|
||||||
Port VictoriaMetrics listens on, bound to loopback only (see
|
|
||||||
below). Upstream's own default, kept so an operator reading
|
|
||||||
VictoriaMetrics documentation finds what they expect.
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
|
|
||||||
};
|
|
||||||
|
|
||||||
# Retention is a property of the store this host runs, not something the
|
# Retention is a property of the store this host runs, not something the
|
||||||
# swarm has to agree on: it is read only where the container is defined,
|
# swarm has to agree on: it is read only where the container is defined,
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue