Compare commits

..
2 changed files with 17 additions and 33 deletions

View file

@ -70,10 +70,6 @@ in
serviceConfig = {
Type = "oneshot";
RemainAfterExit = true;
# What actually bounds the read below. Stated here rather than
# left to systemd's default, so the number a boot waits on is in
# the file that waits.
TimeoutStartSec = 30;
};
environment = {
BAO_ADDR = "https://${baoCfg.domain}:${toString baoCfg.port}";
@ -84,11 +80,9 @@ in
script = ''
set -euo pipefail
# A sealed or uninitialised store answers on the port and never
# answers the read, so "the store is up" is not the same as "the
# store can answer". `TimeoutStartSec` above is the bound; the
# homeserver only `Wants=` this unit, so hitting it degrades to
# keeping the local token rather than holding up the container.
# A sealed or uninitialised store answers on the port and times out on
# every read, so "the store is up" is not the same as "the store can
# answer" -- bound the wait rather than hanging the boot behind it.
if ! token="$(bao kv get -field=value ${lib.escapeShellArg tokenPath} 2>/dev/null)"; then
echo "swarm-bao holds no ${tokenPath}, or is sealed/unreachable." >&2
echo "Keeping the token hive-matrix already has." >&2

View file

@ -23,8 +23,8 @@
# distribute: reach the store to get the CA material, need a cert from that CA
# to reach the store. Service↔store mTLS is therefore its own trust domain,
# separate from the gateway's HTTPS certificates and from both CAs in this
# tree. The cert paths are inputs this module declares no default for and never
# fills in; a glue module mints that identity and points them at it.
# tree. The cert paths are inputs with no defaults and nothing here fills them
# in; whatever comes to mint that identity is what they will point at.
{
pkgs,
lib,
@ -199,13 +199,10 @@ in
Certificate the store serves, covering
{option}`services.hyperhive.swarm.bao.domain`.
This module declares no default and deliberately does not know
what could provide one for the same reason
{option}`services.hyperhive.deploy.bao.clientCaFile` doesn't: the
store never reaches for an authority.
On a hive that runs the store, a glue module supplies a path as a
`mkDefault`, so naming your own here wins over it.
No default, and this module deliberately does not know what could
provide one for the same reason
{option}`services.hyperhive.deploy.bao.clientCaFile` doesn't. The
deployment names the file; the store never reaches for an authority.
A path, never a value.
'';
@ -229,14 +226,11 @@ in
description = ''
Authority the store validates hive **client** certificates against.
This module declares no default and does not reach for the hive
CA: the hive CA is a future *consumer* of the store, so a store
that authenticated against it could not come up before the thing
it issues.
On a hive that runs the store, a glue module supplies the CA it
minted for exactly this, as a `mkDefault`. Point this at something
else the swarm root, an operator's own CA and yours wins.
Deliberately has no default, and does not reach for the hive CA:
the hive CA is a future *consumer* of the store, so a store that
authenticated against it could not come up before the thing it
issues. It is a value someone points at the swarm root for a
swarm that runs one, an operator's own CA otherwise.
`null` leaves client-certificate verification off, which is only
appropriate where something else authenticates the connection.
@ -334,14 +328,10 @@ in
The swarm secret store has no server certificate: set both
services.hyperhive.deploy.bao.serverCertFile and .serverKeyFile.
This module defaults neither, on purpose a store must not
take its identity from an authority it will itself distribute,
and service-to-store mTLS is a separate trust domain from the
Nothing defaults them, on purpose a store must not take its
identity from an authority it will itself distribute, and
service-to-store mTLS is a separate trust domain from the
gateway's certificates and from either CA in this tree.
A hive that runs the store normally gets both from a glue
module, so reaching this means that glue is absent or
something set these back to null.
'';
}
];