diff --git a/nix/host-modules/glue-matrix-bao-token.nix b/nix/host-modules/glue-matrix-bao-token.nix index fbc703b4..a89db5b3 100644 --- a/nix/host-modules/glue-matrix-bao-token.nix +++ b/nix/host-modules/glue-matrix-bao-token.nix @@ -70,10 +70,6 @@ in serviceConfig = { Type = "oneshot"; RemainAfterExit = true; - # What actually bounds the read below. Stated here rather than - # left to systemd's default, so the number a boot waits on is in - # the file that waits. - TimeoutStartSec = 30; }; environment = { BAO_ADDR = "https://${baoCfg.domain}:${toString baoCfg.port}"; @@ -84,11 +80,9 @@ in script = '' set -euo pipefail - # A sealed or uninitialised store answers on the port and never - # answers the read, so "the store is up" is not the same as "the - # store can answer". `TimeoutStartSec` above is the bound; the - # homeserver only `Wants=` this unit, so hitting it degrades to - # keeping the local token rather than holding up the container. + # A sealed or uninitialised store answers on the port and times out on + # every read, so "the store is up" is not the same as "the store can + # answer" -- bound the wait rather than hanging the boot behind it. if ! token="$(bao kv get -field=value ${lib.escapeShellArg tokenPath} 2>/dev/null)"; then echo "swarm-bao holds no ${tokenPath}, or is sealed/unreachable." >&2 echo "Keeping the token hive-matrix already has." >&2 diff --git a/nix/host-modules/swarm-bao.nix b/nix/host-modules/swarm-bao.nix index 54e182b8..37802f39 100644 --- a/nix/host-modules/swarm-bao.nix +++ b/nix/host-modules/swarm-bao.nix @@ -23,8 +23,8 @@ # distribute: reach the store to get the CA material, need a cert from that CA # to reach the store. Service↔store mTLS is therefore its own trust domain, # separate from the gateway's HTTPS certificates and from both CAs in this -# tree. The cert paths are inputs this module declares no default for and never -# fills in; a glue module mints that identity and points them at it. +# tree. The cert paths are inputs with no defaults and nothing here fills them +# in; whatever comes to mint that identity is what they will point at. { pkgs, lib, @@ -199,13 +199,10 @@ in Certificate the store serves, covering {option}`services.hyperhive.swarm.bao.domain`. - This module declares no default and deliberately does not know - what could provide one — for the same reason - {option}`services.hyperhive.deploy.bao.clientCaFile` doesn't: the - store never reaches for an authority. - - On a hive that runs the store, a glue module supplies a path as a - `mkDefault`, so naming your own here wins over it. + No default, and this module deliberately does not know what could + provide one — for the same reason + {option}`services.hyperhive.deploy.bao.clientCaFile` doesn't. The + deployment names the file; the store never reaches for an authority. A path, never a value. ''; @@ -229,14 +226,11 @@ in description = '' Authority the store validates hive **client** certificates against. - This module declares no default and does not reach for the hive - CA: the hive CA is a future *consumer* of the store, so a store - that authenticated against it could not come up before the thing - it issues. - - On a hive that runs the store, a glue module supplies the CA it - minted for exactly this, as a `mkDefault`. Point this at something - else — the swarm root, an operator's own CA — and yours wins. + Deliberately has no default, and does not reach for the hive CA: + the hive CA is a future *consumer* of the store, so a store that + authenticated against it could not come up before the thing it + issues. It is a value someone points at — the swarm root for a + swarm that runs one, an operator's own CA otherwise. `null` leaves client-certificate verification off, which is only appropriate where something else authenticates the connection. @@ -334,14 +328,10 @@ in The swarm secret store has no server certificate: set both services.hyperhive.deploy.bao.serverCertFile and .serverKeyFile. - This module defaults neither, on purpose — a store must not - take its identity from an authority it will itself distribute, - and service-to-store mTLS is a separate trust domain from the + Nothing defaults them, on purpose — a store must not take its + identity from an authority it will itself distribute, and + service-to-store mTLS is a separate trust domain from the gateway's certificates and from either CA in this tree. - - A hive that runs the store normally gets both from a glue - module, so reaching this means that glue is absent or - something set these back to null. ''; } ];