The queue listened in plaintext on 4222, reached by bridge IP or loopback,
and nothing in-tree opened it to another hive. It now has a name, serves a
certificate for that name alone, and refuses clients that do not speak TLS.
- `swarm.nats.domain`, default `nats.<swarm.domain>`, a sibling name like
`swarm.bao.domain`. The queue host answers it via `gateway.localNames`;
every other hive resolves it through the operator's DNS, as for bao.
- `pki/roles/swarm-nats` allows that one name (bare domain, no subdomains,
IPs or localhost, server flag). A `swarm-nats` cert-auth role and policy
may only `update` `pki/issue/swarm-nats`, written by
`swarm-bao-nats-tls-policy`. The login leaf is minted by glue-bao-tls and
paired by glue-nats-bao-identity. `deploy.bao.natsCommonName` is reserved
as a hive name.
- `swarm-bao-nats-tls` issues the leaf into a directory bound read-only into
the container, restarts nats when it rotates, and re-runs daily.
It joins glue-bao-readers-policy-order, so it is ordered after its policy
unit (`after` and `wants`, never `requires`) where the store is on the
same host. The policy unit joins the store's journald list.
- nats gets `tls {}`, with the key via `LoadCredential`, and no
`allow_non_tls`. `validateConfig` is now off in every mode, because the
build-time check loads a leaf that only exists at runtime.
- 4222 is also open on `wg-hive` when the host is on the mesh, never
host-wide.
- `statusPublish.natsUrl`, `queue.agentNatsUrl`, the controller's URL under
`singleHostSwarm`, and the auth responder all dial
`tls://<swarm.nats.domain>:<port>`. swarm-queue-client hands its CA file
to the NATS connection too, so hive-c0re and the controller trust the
leaf's root.
- docs/swarm/README.md: the queue URL and the one DNS record a multi-host
swarm needs.
module-eval-nats-tls pins the role, the policy, the served leaf, the
firewall, the ordering, and a scan of every `*_NATS_URL` and the
responder's URL across the host and its containers.
Closes #4626
62 lines
2.4 KiB
Nix
62 lines
2.4 KiB
Nix
# Glue: where the store and one of its readers share a host, the reader waits
|
|
# for the unit that writes the cert-auth role it logs in with.
|
|
#
|
|
# ONE PAIRING PER FILE — the store's reader policy units ← the readers
|
|
# they grant, and nothing else. Deleting this leaves every reader as it is on a
|
|
# host whose store is remote: it may log in before its role exists, and its own
|
|
# retries are what carry it past that.
|
|
#
|
|
# ⚠️ Gated on BOTH the store and that reader being here. Off the store's host
|
|
# there is no local policy unit to order against. On the store's host without
|
|
# the reader, setting `systemd.services.<reader>.after` would define a unit
|
|
# with no ExecStart, so each gate below restates the one the reader's own
|
|
# module puts on it. A reader whose gate changes must change here too.
|
|
#
|
|
# Ordering, never a requirement: a policy unit skips once the bootstrap token
|
|
# is gone, and a skipped unit counts as done. `wants` as well as `after`, so a
|
|
# reader started on its own pulls its policy unit into the same transaction.
|
|
{
|
|
lib,
|
|
config,
|
|
...
|
|
}:
|
|
let
|
|
hyperhiveCfg = config.services.hyperhive;
|
|
deployCfg = hyperhiveCfg.deploy;
|
|
baoDeploy = deployCfg.bao;
|
|
|
|
havePair = cert: key: cert != null && key != null;
|
|
|
|
# Reader unit → the gate its own module defines it under.
|
|
readersHere = {
|
|
# ./glue-matrix-bao-token.nix
|
|
swarm-bao-matrix-token =
|
|
hyperhiveCfg.enable
|
|
&& havePair baoDeploy.matrixTokenClientCertFile baoDeploy.matrixTokenClientKeyFile
|
|
&& deployCfg.matrix.enable;
|
|
# ./glue-queue-agent-credential.nix
|
|
swarm-bao-queue-agent =
|
|
hyperhiveCfg.enable
|
|
&& havePair baoDeploy.queueAgentClientCertFile baoDeploy.queueAgentClientKeyFile;
|
|
# ./swarm-grafana.nix
|
|
swarm-bao-grafana-oidc = hyperhiveCfg.enable && deployCfg.grafana.enable;
|
|
# ./swarm-otel.nix
|
|
swarm-bao-otel-oidc =
|
|
deployCfg.swarm-otel.enable
|
|
&& havePair baoDeploy.otelOidcClientCertFile baoDeploy.otelOidcClientKeyFile;
|
|
# ./swarm-nats.nix: the queue's TLS leaf, not a secret, but the same wait.
|
|
swarm-bao-nats-tls = deployCfg.nats.enable;
|
|
};
|
|
|
|
orderAfterPolicy =
|
|
reader: here:
|
|
lib.mkIf (baoDeploy.enable && here) {
|
|
systemd.services.${reader} = {
|
|
after = [ "${reader}-policy.service" ];
|
|
wants = [ "${reader}-policy.service" ];
|
|
};
|
|
};
|
|
in
|
|
{
|
|
config = lib.mkMerge (lib.mapAttrsToList orderAfterPolicy readersHere);
|
|
}
|