diff --git a/docs/observability.md b/docs/observability.md index 46f87bbd..4b23a4bb 100644 --- a/docs/observability.md +++ b/docs/observability.md @@ -208,26 +208,22 @@ a build error naming the reason rather than telemetry silently going nowhere. ## Network access -Agent containers can only reach the host on ports 80 and 443 by default. If -your OTLP collector runs on a non-standard port on the same host (e.g. a local -dev collector on `:4318`), open that port via: +Agent containers can only reach the host on ports 80 and 443 by default. To let +them reach some other host-local service you run yourself — a database, a +scratch HTTP endpoint — open its port on the bridge: ```nix -services.hyperhive.network.exposeHostPorts = [ 4318 ]; +services.hyperhive.network.exposeHostPorts = [ 5432 ]; ``` -Then point the endpoint at the bridge IP rather than loopback: +and point whatever consumes it at `10.42.0.1:5432` rather than loopback: inside +a container, loopback is the *container*. The bridge IP is the host's address on +the `hive-br0` bridge. The service must also bind an address the bridge can +reach — a `127.0.0.1`-only listener stays unreachable no matter what the +firewall allows. See `docs/network.md::Reaching host services` for details. -```nix -services.hyperhive.otel.endpoint = "http://10.42.0.1:4318"; -``` - -The bridge IP is the host's address on the `hvbr0` bridge, typically -`10.42.0.1`. See `docs/network.md::Reaching host services` for details. - -⚠️ **You do not need either line for hyperhive's own telemetry** — `otel.enable` -contributes the collector's port and derives the endpoint itself. The above is -for pointing something *else* at a host-local service. +⚠️ **None of this is needed for hyperhive's own telemetry** — `otel.enable` +contributes the collector's port and derives the agent-facing endpoint itself. ## Built-in resource labels diff --git a/nix/host-modules/hive-network.nix b/nix/host-modules/hive-network.nix index ff182902..957e5caf 100644 --- a/nix/host-modules/hive-network.nix +++ b/nix/host-modules/hive-network.nix @@ -93,7 +93,7 @@ in exposeHostPorts = lib.mkOption { type = lib.types.listOf lib.types.port; default = [ ]; - example = [ 4318 ]; + example = [ 5432 ]; description = '' TCP ports on the host that agent containers may reach at the bridge IP (`bridgeIp`). Each listed port `P` is opened on the bridge-interface @@ -104,12 +104,6 @@ in a database, a scratch HTTP endpoint, anything listening on `''${bridgeIp}:P`. - Not needed for hyperhive's own telemetry: `services.hyperhive.otel.enable` - contributes its collector's port here itself and derives the - agent-facing endpoint from the bridge address. `otel.endpoint` names - where telemetry goes *after it leaves the swarm*, and is read by the - swarm's collector — it is not a bridge address. - **The host service must bind an address reachable from the bridge** — `0.0.0.0` or the bridge IP (`bridgeIp`) — not loopback-only. The bridge→`127.0.0.0/8` DROP rule (defence-in-depth) is unchanged: this