refactor(gateway): make the gateway unconditional — remove gateway.enable
The gateway container starts alongside every hyperhive deployment, so gating it behind a separate enable flag was a footgun: an operator who set it false lost the only thing exposed to the outside while the agent containers kept running. Re-gate the gateway config on the top-level services.hyperhive.enable instead. - hive-gateway.nix: drop the gateway.enable mkOption; gate the config block on config.services.hyperhive.enable. - hive-forge.nix: behindGateway now defaults to services.hyperhive.enable; remove the behindGateway-requires-gateway assertion (now vacuous). - hive-network.nix: remove both gateway.enable assertions (vacuous). - hive-c0re.nix: drop the firewall.allowedTCPPortRanges 8100-8999 fallback that opened agent ports when the gateway was off (the gateway is now the sole entry point); HIVE_GATEWAY_ENABLED is always set since the gateway always runs. - nix/docs/default.nix: remove the gateway.enable = mkForce false stub (would be an eval error against the removed option; the gateway is already re-gated on hyperhive.enable, which docs force false). - hive-matrix.nix, dashboard.rs: comment/prose updates only. BREAKING: operators relying on services.hyperhive.gateway.enable = false to suppress the gateway must instead point their own reverse proxy at the gateway's port. NixOS errors clearly on the now-unknown option.
This commit is contained in:
parent
d9c66de069
commit
fdf05c1673
7 changed files with 34 additions and 86 deletions
|
|
@ -69,22 +69,11 @@ in
|
|||
# `docs/gateway.md`.
|
||||
|
||||
options.services.hyperhive.gateway = {
|
||||
enable = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = true;
|
||||
description = ''
|
||||
Run hive-gateway — a single nginx in front of every hyperhive
|
||||
surface. On by default: the gateway hosts the matrix GUI static
|
||||
dist (when `services.hyperhive.matrix.gui.enable` is true) and
|
||||
proxies everything else to hive-c0re's dashboard upstream. Set
|
||||
`services.hyperhive.gateway.enable = false` to bypass nginx
|
||||
entirely and reach hive-c0re directly on its dashboard port
|
||||
(7000 by default).
|
||||
|
||||
v0 is HTTP-only; TLS / public-domain shape is tracked
|
||||
separately.
|
||||
'';
|
||||
};
|
||||
# The gateway is always run alongside hyperhive (it's the single nginx
|
||||
# in front of every surface and the only thing exposed to the outside);
|
||||
# there is no enable flag. An operator who wants their own reverse proxy
|
||||
# in front points it at the gateway's `port`. The gateway config below
|
||||
# is gated on the top-level `services.hyperhive.enable`.
|
||||
|
||||
port = lib.mkOption {
|
||||
type = lib.types.port;
|
||||
|
|
@ -375,7 +364,7 @@ in
|
|||
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
config = lib.mkIf config.services.hyperhive.enable {
|
||||
assertions = [
|
||||
{
|
||||
assertion = !cfg.localHostsEntry || hyperhiveDomain != null;
|
||||
|
|
|
|||
Loading…
Reference in a new issue