# Glue: point the queue's auth-callout responder at the bao leaf minted for it. # # ONE PAIRING PER FILE — the swarm-nats-auth principal ← bao, and nothing else. # Deleting this leaves a responder with no store identity unless the operator # names one: every agent token is then denied, and OIDC clients are unaffected. # # ⚠️ The minting is NOT here. ./glue-bao-tls.nix holds the CA and signs the # leaf. What belongs here is the pairing: which paths the responder presents. # # ⚠️ Gated on the leaf existing, not on the store being enabled, for the reason # ./glue-nats-bao-identity.nix states: the hive hosting the queue need not be # the hive hosting the store. # # Everything is `mkDefault`. An operator naming their own paths wins. { lib, config, ... }: let hyperhiveCfg = config.services.hyperhive; deployCfg = hyperhiveCfg.deploy; baoDeploy = deployCfg.bao; # Where ./glue-bao-tls.nix puts the leaves, derived from the reader's own path # rather than repeating that file's directory literal. haveMintedPki = baoDeploy.clientCertFile != null; pkiDir = if haveMintedPki then builtins.dirOf baoDeploy.clientCertFile else null; in { config = lib.mkIf (hyperhiveCfg.enable && deployCfg.nats.enable && haveMintedPki) { services.hyperhive.deploy.nats = { authBaoClientCertFile = lib.mkDefault "${pkiDir}/nats-auth.pem"; authBaoClientKeyFile = lib.mkDefault "${pkiDir}/nats-auth-key.pem"; }; }; }