atlas
9f3f01450b
swarm-bao: keep the raft state in the container, bind only the TLS material
...
The state directory was bind-mounted from the host so a nixos-container
destroy could not take the swarm's secrets with it. No sibling service does
that -- swarm-grafana keeps its sqlite database inside the container on
ephemeral = false -- and the bind is what broke the store: upstream pairs
StateDirectory= with DynamicUser=, systemd relocates the state to
/var/lib/private/openbao, and that rename fails EBUSY on an active mount
point, so the unit died at STATE_DIRECTORY before bao ever ran.
The TLS material still has to cross the boundary, because a host unit writes
it and the container reads it, so it moves to its own small bind at
/var/lib/swarm-bao-tls rather than riding along in the state directory. That
directory is 0755 and read-only inside: the certificate and client CA are
public and are read straight off the mount.
The private key is not. install -m 0600 leaves it root-owned and the service
runs as a DynamicUser, so the bind-mounted file is unreadable to it -- which
the old layout hid, because StateDirectory chowned the whole tree on the way
past. LoadCredential is systemd's mechanism for precisely this: PID 1 opens
the source as root and re-exposes it inside the unit owned by the service's
own account.
2026-08-31 00:33:37 +02:00
..
hive-c0re
deploy: move the hive CA's knobs to deploy.hive-controller.tls
2026-08-30 20:52:00 +02:00
hive-forge
deploy: move the hive CA's knobs to deploy.hive-controller.tls
2026-08-30 20:52:00 +02:00
hive-gateway
deploy: move the hive CA's knobs to deploy.hive-controller.tls
2026-08-30 20:52:00 +02:00
lib
deploy: move the hive CA's knobs to deploy.hive-controller.tls
2026-08-30 20:52:00 +02:00
swarm-grafana /dashboards
grafana: rank the by-label panel as bars, and stop calling it open issues
2026-08-28 13:23:25 +02:00
default.nix
glue-matrix-bao-token: the store's first reader
2026-08-30 19:01:10 +02:00
deploy.nix
deploy: move the hive CA's knobs to deploy.hive-controller.tls
2026-08-30 20:52:00 +02:00
glue-bao-tls.nix
glue-bao-tls: mint the store an identity it can hold before it is up
2026-08-30 19:01:10 +02:00
glue-matrix-bao-token.nix
glue-matrix-bao-token: state the bound the comment claims
2026-08-30 19:10:48 +02:00
hive-ci.nix
deploy: move the hive CA's knobs to deploy.hive-controller.tls
2026-08-30 20:52:00 +02:00
hive-matrix.nix
deploy: move the hive CA's knobs to deploy.hive-controller.tls
2026-08-30 20:52:00 +02:00
hive-network.nix
require network isolation, deleting the residual non-isolated branch
2026-08-30 03:32:08 +02:00
hive-priv.nix
fix( #2573 ): also add /etc/tmpfiles.d to hive-priv ReadWritePaths (same EROFS class)
2026-07-18 16:39:20 +02:00
hive-tls.nix
deploy: move the hive CA's knobs to deploy.hive-controller.tls
2026-08-30 20:52:00 +02:00
hyperhive.nix
deploy: rename enableAllLocalDefaults to deploy.singleHostSwarm
2026-08-30 20:12:16 +02:00
local-defaults.nix
deploy: rename enableAllLocalDefaults to deploy.singleHostSwarm
2026-08-30 20:12:16 +02:00
otel.nix
deploy: move the hive CA's knobs to deploy.hive-controller.tls
2026-08-30 20:52:00 +02:00
stylix-theme.nix
swarm-ui: apply the operator's stylix theme, same as the dashboard already does
2026-08-24 14:28:25 +02:00
swarm-authelia.nix
deploy: rename swarm.enableRequiredServices to deploy.allSwarmServices
2026-08-30 20:12:16 +02:00
swarm-bao.nix
swarm-bao: keep the raft state in the container, bind only the TLS material
2026-08-31 00:33:37 +02:00
swarm-ca.nix
deploy: move the hive CA's knobs to deploy.hive-controller.tls
2026-08-30 20:52:00 +02:00
swarm-container-resolver.nix
fix( #3363 ): swarm containers write their own resolver file
2026-08-17 17:30:15 +02:00
swarm-controller.nix
deploy: move the hive CA's knobs to deploy.hive-controller.tls
2026-08-30 20:52:00 +02:00
swarm-grafana.nix
deploy: name the swarm collector swarm-otel, not otel
2026-08-30 04:23:22 +02:00
swarm-nats.nix
deploy: move the hive CA's knobs to deploy.hive-controller.tls
2026-08-30 20:52:00 +02:00
swarm-otel.nix
deploy: name the swarm collector swarm-otel, not otel
2026-08-30 04:23:22 +02:00
swarm-peers-removed.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm-required-services.nix
deploy: rename enableAllLocalDefaults to deploy.singleHostSwarm
2026-08-30 20:12:16 +02:00
swarm-snapshot-store.nix
refactor( #2862 ): keep the option at services.hyperhive.snapshotStore
2026-07-31 19:03:24 +02:00
swarm-ui.nix
deploy: give every option an enable, and name the controller one
2026-08-30 04:23:22 +02:00
swarm-victorialogs.nix
deploy: retention is the store host's decision, not the swarm's
2026-08-30 16:23:48 +02:00
swarm-victoriametrics.nix
deploy: retention is the store host's decision, not the swarm's
2026-08-30 16:23:48 +02:00
swarm-wireguard.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm.nix
deploy: rename enableAllLocalDefaults to deploy.singleHostSwarm
2026-08-30 20:12:16 +02:00