refactor(3202): all-local asserts the host's own /etc/hosts entries
Clause 2 of #3202, reading 1 (mara: "the all local stuff and swarm services auto conf belong in those mods, not spread all over"). `gateway.localHostsEntry` is the gateway's only local-deployment knob — `openFirewall` is about EXTERNAL exposure, `tls.acme` needs a public DNS name, `hsts` is a hardening choice. It is now asserted by the mode in local-defaults.nix, beside the three swarm toggles, instead of being the one all-local implication an operator still had to know about. `mkDefault`, so "all local except this" still needs no new option. ⚠️ The non-obvious half: this does NOT change what CONTAINERS resolve. dnsmasq sets `no-hosts = true` unconditionally, so agents keep getting the bridge IP from the authoritative `address=` rules rather than the host's 127.0.0.1 — which would point every agent at its own netns. That guard already existing is what makes this safe to default on; without it this one line would break every agent's access to the forge.
This commit is contained in:
parent
030eef0948
commit
f80facbbe0
2 changed files with 29 additions and 4 deletions
|
|
@ -91,6 +91,12 @@ in
|
||||||
gateway shape. Off by default — operators running with real
|
gateway shape. Off by default — operators running with real
|
||||||
DNS shouldn't have a stale `/etc/hosts` entry sticking
|
DNS shouldn't have a stale `/etc/hosts` entry sticking
|
||||||
around. Requires `services.hyperhive.domain` to be set.
|
around. Requires `services.hyperhive.domain` to be set.
|
||||||
|
|
||||||
|
`services.hyperhive.enableAllLocalDefaults` turns this on as
|
||||||
|
part of saying "this box is the whole deployment": that mode
|
||||||
|
means there is no real DNS for these names and the operator is
|
||||||
|
browsing them from the host itself. Set it here explicitly to
|
||||||
|
override in either direction.
|
||||||
'';
|
'';
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -29,11 +29,15 @@ in
|
||||||
example = true;
|
example = true;
|
||||||
description = ''
|
description = ''
|
||||||
Run the whole swarm on this host. Turning this on asserts the
|
Run the whole swarm on this host. Turning this on asserts the
|
||||||
swarm-level toggles that an all-on-one-box deployment implies:
|
toggles that an all-on-one-box deployment implies: the swarm's
|
||||||
the swarm's shared services
|
shared services
|
||||||
(`services.hyperhive.swarm.enableRequiredServices`), the swarm
|
(`services.hyperhive.swarm.enableRequiredServices`), the swarm
|
||||||
CA (`services.hyperhive.swarm.ca.autoConfigure`), and the swarm
|
CA (`services.hyperhive.swarm.ca.autoConfigure`), the swarm
|
||||||
controller (`services.hyperhive.swarm.controller.enable`).
|
controller (`services.hyperhive.swarm.controller.enable`), and the
|
||||||
|
host's `/etc/hosts` entries for the names this hive serves
|
||||||
|
(`services.hyperhive.gateway.localHostsEntry`) — with no real DNS
|
||||||
|
for those names, the operator is browsing them from the same box
|
||||||
|
that answers for them.
|
||||||
|
|
||||||
**Off by default, and that is the load-bearing part.** A swarm's
|
**Off by default, and that is the load-bearing part.** A swarm's
|
||||||
services and its hives can live on different hosts, and a host has
|
services and its hives can live on different hosts, and a host has
|
||||||
|
|
@ -52,6 +56,21 @@ in
|
||||||
# own `default` (1500) and loses to any explicit definition, which is
|
# own `default` (1500) and loses to any explicit definition, which is
|
||||||
# exactly the precedence a deployment mode wants: it fills in for an
|
# exactly the precedence a deployment mode wants: it fills in for an
|
||||||
# operator who hasn't spoken, and never argues with one who has.
|
# operator who hasn't spoken, and never argues with one who has.
|
||||||
|
# The gateway's own all-local bit. `localHostsEntry` maps every name
|
||||||
|
# this hive answers for to 127.0.0.1 in the HOST's /etc/hosts, which is
|
||||||
|
# exactly what "this box is the whole deployment" implies: there is no
|
||||||
|
# real DNS for these names, and the operator is browsing them from the
|
||||||
|
# same machine that serves them.
|
||||||
|
#
|
||||||
|
# ⚠️ It does NOT affect what containers resolve. dnsmasq sets
|
||||||
|
# `no-hosts = true` unconditionally (see hive-gateway/dnsmasq.nix), so
|
||||||
|
# agents keep getting the bridge IP from the authoritative `address=`
|
||||||
|
# rules rather than the host's 127.0.0.1 — an entry that would point
|
||||||
|
# every agent at its own netns. That guard already existing is what
|
||||||
|
# makes turning this on by default safe; without it this line would
|
||||||
|
# break every agent's access to the forge.
|
||||||
|
config.services.hyperhive.gateway.localHostsEntry = lib.mkDefault cfg.enableAllLocalDefaults;
|
||||||
|
|
||||||
config.services.hyperhive.swarm = {
|
config.services.hyperhive.swarm = {
|
||||||
enableRequiredServices = lib.mkDefault cfg.enableAllLocalDefaults;
|
enableRequiredServices = lib.mkDefault cfg.enableAllLocalDefaults;
|
||||||
ca.autoConfigure = lib.mkDefault cfg.enableAllLocalDefaults;
|
ca.autoConfigure = lib.mkDefault cfg.enableAllLocalDefaults;
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue