Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/nix/host-modules
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 7eb966fe2b credential units: restart consumers on a changed credential; fix the ordering claim
The previous commit's comments said a unit in auto-restart keeps its
start job, so anything ordered after it waits for the whole 24h retry
window. That is wrong under the default RestartMode=normal: each failed
attempt passes through `failed`, which ends that start job. `After=`
dependents proceed after one attempt, `Requires=` dependents fail with
`dependency`, and the retries continue as fresh start jobs. The
2026-09-24 journal shows it with the already-2880 swarm-services-cert:
nginx got "Dependency failed" 1ms after the first failure, and
switch-to-configuration exited before the first restart was scheduled.
The comments in lib/store-retry.nix, glue-matrix-bao-token.nix,
glue-queue-agent-credential.nix, swarm-otel.nix and swarm-grafana.nix
now say that, and so does docs/swarm/credentials.md.

Because dependents start after one attempt, a consumer that loads its
credential at start never sees a value a later attempt lands, or a
rotated one. nix/host-modules/lib/refresh-consumer.nix adds
`secret_differs` and `refresh_consumer`, and the four fetch units whose
consumers take a start-time copy call them after the write, only when
the value changed:

- swarm-bao-matrix-token -> tuwunel.service in hive-matrix
- swarm-bao-otel-oidc -> opentelemetry-collector.service in swarm-otel
- swarm-bao-grafana-oidc -> grafana.service in the grafana container
- swarm-bao-forwarder-oidc -> opentelemetry-collector.service in swarm-bao

A running consumer is try-restarted, a failed one is reset and started,
all with --no-block. Inline in the fetch script rather than a
PathChanged path unit because the fetch script is the only writer and
already knows whether the value changed, and it is the same shape as
this PR's nginx hook and swarm-bao-nats-tls's restart of nats.

module-eval-bao-grants gains one case per consumer.

Refs #4662
2026-09-30 07:45:47 +02:00
..
hive-c0re hive-priv: create agent socket dirs on start; drop hyperhive-agents.conf 2026-09-27 18:55:33 +02:00
hive-forge nix: move the remaining service containers onto the swarm-container module 2026-09-29 20:17:28 +02:00
hive-gateway hive-priv: create agent socket dirs on start; drop hyperhive-agents.conf 2026-09-27 18:55:33 +02:00
lib credential units: restart consumers on a changed credential; fix the ordering claim 2026-09-30 07:45:47 +02:00
swarm-grafana/dashboards swarm-grafana: revert busiest-agents table, restore bargauges (#4658) 2026-09-28 11:52:33 +02:00
bao-bootstrap-policy.hcl bao: disable the unused approle auth method, declaratively 2026-09-28 22:58:36 +02:00
default.nix bao: OIDC login to the browser UI via authelia, as a metadata-only viewer 2026-09-28 19:56:38 +02:00
deploy.nix swarm-controller: read the queue client secret from the store, drop the file 2026-09-28 19:01:05 +02:00
glue-bao-readers-policy-order.nix swarm-bao: write every swarm-* grant as a bao granter, not with a 24h token 2026-09-27 22:57:46 +02:00
glue-bao-tls.nix swarm-nats-auth: verify an agent's own token against the store 2026-09-28 08:24:52 +02:00
glue-bao-ui-oidc-client.nix bao: OIDC login to the browser UI via authelia, as a metadata-only viewer 2026-09-28 19:56:38 +02:00
glue-controller-bao-identity.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
glue-forge-oidc-client.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
glue-grafana-oidc-client.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
glue-matrix-bao-token.nix credential units: restart consumers on a changed credential; fix the ordering claim 2026-09-30 07:45:47 +02:00
glue-matrix-ctl-bao-identity.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
glue-nats-auth-bao-identity.nix swarm-nats-auth: verify an agent's own token against the store 2026-09-28 08:24:52 +02:00
glue-nats-bao-identity.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
glue-queue-agent-credential.nix credential units: restart consumers on a changed credential; fix the ordering claim 2026-09-30 07:45:47 +02:00
glue-secret-publisher-bao-identity.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
glue-services-issuer-bao-identity.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
glue-swarm-bao-otel-oidc-client.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
glue-swarm-otel-oidc-client.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
hive-ci.nix nix: move the remaining service containers onto the swarm-container module 2026-09-29 20:17:28 +02:00
hive-matrix.nix bao: drop matrix-ctl's per-hive sender-token grant 2026-09-30 07:42:22 +02:00
hive-network.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
hive-priv.nix hive-priv: create agent socket dirs on start; drop hyperhive-agents.conf 2026-09-27 18:55:33 +02:00
hive-tls.nix credential units: 24h retry shape; start a failed nginx when the cert lands 2026-09-30 07:45:47 +02:00
hyperhive.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
local-defaults.nix swarm-controller: read the queue client secret from the store, drop the file 2026-09-28 19:01:05 +02:00
otel.nix otel.nix: trim the StartLimit comment block to the load-bearing points 2026-09-23 17:22:51 +02:00
stylix-theme.nix swarm-ui: apply the operator's stylix theme, same as the dashboard already does 2026-08-24 14:28:25 +02:00
swarm-authelia.nix nix: move the remaining service containers onto the swarm-container module 2026-09-29 20:17:28 +02:00
swarm-bao.nix credential units: restart consumers on a changed credential; fix the ordering claim 2026-09-30 07:45:47 +02:00
swarm-ca.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
swarm-controller.nix swarm-controller: read the queue client secret from the store, drop the file 2026-09-28 19:01:05 +02:00
swarm-grafana.nix credential units: restart consumers on a changed credential; fix the ordering claim 2026-09-30 07:45:47 +02:00
swarm-nats.nix nix: move the remaining service containers onto the swarm-container module 2026-09-29 20:17:28 +02:00
swarm-otel.nix credential units: restart consumers on a changed credential; fix the ordering claim 2026-09-30 07:45:47 +02:00
swarm-peers-removed.nix docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
swarm-required-services.nix nix: run the forge on one host per swarm (deploy.forgejo.enable) 2026-09-24 23:56:07 +02:00
swarm-secret-publisher.nix bao: OIDC login to the browser UI via authelia, as a metadata-only viewer 2026-09-28 19:56:38 +02:00
swarm-snapshot-store.nix deploy: move the wireguard mesh out of the namespace hives read 2026-09-07 14:24:52 +02:00
swarm-ui.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
swarm-victorialogs.nix nix: move the remaining service containers onto the swarm-container module 2026-09-29 20:17:28 +02:00
swarm-victoriametrics.nix nix: move the in-container modules to nix/container-modules/ 2026-09-29 19:51:46 +02:00
swarm-wireguard.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
swarm.nix bao: serve the browser UI to admins via a loopback-only listener 2026-09-28 19:31:02 +02:00