Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/nix/host-modules/swarm-container.nix
atlas 024067f3f8 nix: share the service-container settings through one in-container module
The ten hand-rolled `containers.<name>` blocks each repeat the same
in-container lines: `system.stateVersion`, a firewall turned off because
the container shares the host netns, and resolvconf forced off because
something in the container writes /etc/resolv.conf itself.

`nix/host-modules/swarm-container.nix` now owns those lines. It is
imported inside the container's own config and exposes
`services.hyperhive.swarmContainer.{privateNetwork,writesOwnResolvConf}`
for the host module to set. `stateVersion` is a `mkDefault`, so the two
containers on another value can keep theirs. `--link-journal=host` stays
per module, and so do the host-side attrs (autoStart, ephemeral,
privateNetwork, bindMounts).

swarm-victoriametrics is converted as the first user. Its container
toplevel drvPath is unchanged. A module-eval case now forces that
container's config, which nothing in the suite read before.

Refs #3773
2026-09-29 19:51:46 +02:00

52 lines
1.8 KiB
Nix

# What every hyperhive service nixos-container sets for itself, imported
# inside the container's own `config`.
#
# The host module that declares `containers.<name>` sets the options below.
# They restate host-side facts the container cannot read on its own: its
# evaluation is nested inside `containers.<name>`, and reading the host side
# back from in here recurses.
{ config, lib, ... }:
let
cfg = config.services.hyperhive.swarmContainer;
in
{
options.services.hyperhive.swarmContainer = {
privateNetwork = lib.mkOption {
type = lib.types.bool;
description = ''
Must equal the host-side `containers.<name>.privateNetwork`. When
`false` the container shares the host netns, so its own
firewall.service would rewrite the HOST ruleset at every boot; the
container's firewall is turned off and the host firewall owns all
filtering.
'';
};
writesOwnResolvConf = lib.mkOption {
type = lib.types.bool;
default = true;
description = ''
Something in this container writes `/etc/resolv.conf` itself (the
`swarm-container-resolver.nix` unit, or a static file), so
resolvconf is forced off. Left on, host-tracking would regenerate the
file empty, since the host's copy doesn't cross the boundary after
start.
'';
};
};
config = lib.mkMerge [
{
# A container that sets its own keeps it. Changing this value changes
# it for every container that doesn't, and that is a state migration
# for each of them.
system.stateVersion = lib.mkDefault "26.05";
}
(lib.mkIf (!cfg.privateNetwork) {
networking.firewall.enable = false;
})
(lib.mkIf cfg.writesOwnResolvConf {
networking.resolvconf.enable = lib.mkForce false;
})
];
}