müde
8a0ecb307b
gateway: pin the Host header when dialing swarm services by name
...
verifiedProxyTo (43ae164d ) verified TLS but left Host to nixpkgs'
recommendedProxySettings, which sets Host to the CALLING vhost, not
the target. Since every consumer resolves back to this same gateway,
nginx picks the vhost to answer by Host header (not by the SNI
proxy_ssl_name already sends) — so every auth subrequest looped back
into its own vhost's auth_request, recursing until nginx's subrequest
depth limit turned it into a 500, on every domain gated by SSO.
Pin Host (and the rest of the header set nixpkgs' recommended include
would otherwise still be the one to set) inside verifiedProxyTo, and
set recommendedProxySettings = false on each of the four call sites so
nixpkgs' own copy — appended after a location's extraConfig — can't
clobber it back.
2026-08-27 20:04:40 +02:00
..
hive-c0re
types: let nix own the reserved-name blacklist
2026-08-27 16:36:42 +02:00
hive-forge
gateway: pin the Host header when dialing swarm services by name
2026-08-27 20:04:40 +02:00
hive-gateway
gateway: pin the Host header when dialing swarm services by name
2026-08-27 20:04:40 +02:00
lib
fix( #3527 ): a missing source must report as zero, not as empty
2026-08-19 20:27:00 +02:00
swarm-grafana /dashboards
swarm-grafana: provision log store and metrics store dashboards
2026-08-26 21:37:31 +02:00
default.nix
feat(swarm-victorialogs): a log store for the swarm
2026-08-24 16:36:18 +02:00
hive-ci.nix
ci: let the runner execute what it builds
2026-08-27 14:48:47 +02:00
hive-matrix.nix
forge, matrix: SSO is not optional
2026-08-24 23:06:25 +02:00
hive-network.nix
docs(network): drop the otel reasoning instead of restating it
2026-08-19 02:04:57 +02:00
hive-priv.nix
fix( #2573 ): also add /etc/tmpfiles.d to hive-priv ReadWritePaths (same EROFS class)
2026-07-18 16:39:20 +02:00
hive-tls.nix
fix( #3462 ): apply the name check in the unit that runs on the deploy
2026-08-18 21:54:38 +02:00
hyperhive.nix
refactor(nix): a hive's domain comes out of the swarm directory
2026-08-05 22:43:17 +02:00
local-defaults.nix
fix( #3343 ): move the all-local queue derivations into the deployment mode
2026-08-16 19:37:49 +02:00
otel.nix
otel: give host metrics a host identity via resourcedetection
2026-08-27 10:49:30 +02:00
stylix-theme.nix
swarm-ui: apply the operator's stylix theme, same as the dashboard already does
2026-08-24 14:28:25 +02:00
swarm-authelia.nix
swarm-authelia: stop answering machine callers with a 200 error page
2026-08-27 14:04:18 +02:00
swarm-ca.nix
swarm-otel: collect only the units the swarm's services declare
2026-08-24 22:05:45 +02:00
swarm-container-resolver.nix
fix( #3363 ): swarm containers write their own resolver file
2026-08-17 17:30:15 +02:00
swarm-controller.nix
types: let nix own the reserved-name blacklist
2026-08-27 16:36:42 +02:00
swarm-grafana.nix
swarm-grafana: provision log store and metrics store dashboards
2026-08-26 21:37:31 +02:00
swarm-nats.nix
swarm-nats: manual callout needs all four keys, not two
2026-08-24 23:06:59 +02:00
swarm-otel.nix
types: let nix own the reserved-name blacklist
2026-08-27 16:36:42 +02:00
swarm-peers-removed.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm-required-services.nix
feat(swarm): start the log store with the other required services
2026-08-24 17:00:38 +02:00
swarm-snapshot-store.nix
refactor( #2862 ): keep the option at services.hyperhive.snapshotStore
2026-07-31 19:03:24 +02:00
swarm-ui.nix
gateway: pin the Host header when dialing swarm services by name
2026-08-27 20:04:40 +02:00
swarm-victorialogs.nix
gateway: pin the Host header when dialing swarm services by name
2026-08-27 20:04:40 +02:00
swarm-victoriametrics.nix
swarm-otel: collect only the units the swarm's services declare
2026-08-24 22:05:45 +02:00
swarm-wireguard.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm.nix
swarm: publish an authenticated gateway vhost for VictoriaLogs
2026-08-24 18:43:26 +02:00