Renames `swarm-matrix-minter` and reshapes it around subcommands. Minting is now `swarm-matrix-ctl mint`. Running rust inside `containers.hive-matrix` is not free: it needs its own store identity, its own cert role and its own bind mounts, and every one of those is per-*container*, not per-task. A second single-purpose crate would have had to duplicate that plumbing to add one action, so the next thing that has to run in there should be a verb here rather than a new crate. The old name guaranteed the opposite. `main.rs` is clap dispatch; the minting logic moves to `mint.rs` unchanged. A bare invocation is refused: `mint` writes a credential, so "no verb" defaulting to it would make a typo in the unit mint rather than fail. The environment prefix moves with it, `MATRIX_MINTER_*` → `MATRIX_MINT_*`. Scoped to the verb and not to the binary, because a binary-scoped prefix is one the next verb has to share or widen, and a widened one never narrows again. A test asserts every variable carries the verb's prefix. The principal renames too. The cert role, bao policy, granting unit, leaf filename and `certAuthCns` entry all have to spell one string the same way, so leaving them as `swarm-matrix-minter` would have rebuilt the naming split this branch exists to remove. Renaming the nix options alongside is free here: every one of them is introduced by this PR and has never been released, so no operator config names them yet. `ExecStart` now names the verb, which is a contract between a nix string and a clap enum that fails at deploy time with no local signal. Both ends assert it: `mint_is_spelled_the_way_the_unit_invokes_it` in the crate, and a new module-eval arm reading the rendered `ExecStart`. docs/getting-started/setup.md drops the sender token from its "live on the host" list: setup does not touch this credential, so a setup guide has no reason to name it.
138 lines
5.5 KiB
Nix
138 lines
5.5 KiB
Nix
# `checks.module-eval-name-guards` — see ./lib.nix for the shared
|
|
# rationale (why this suite exists, naming convention, "evaluates
|
|
# not executes").
|
|
{
|
|
pkgs,
|
|
lib,
|
|
self,
|
|
nixosSystem,
|
|
}:
|
|
let
|
|
inherit
|
|
(import ./lib.nix {
|
|
inherit
|
|
pkgs
|
|
lib
|
|
self
|
|
nixosSystem
|
|
;
|
|
})
|
|
hive
|
|
runGroup
|
|
;
|
|
|
|
# The hive-name guards, with the collector explicitly OFF. That is the whole
|
|
# property: the guards live where `swarm.hives` is declared, so they run in a
|
|
# deployment that has a secret store and no collector — which used to skip
|
|
# them entirely, because they were assertions inside swarm-otel's own `mkIf`.
|
|
#
|
|
# ⚠️ `controllerCommonName` is overridden to a name containing NO reserved
|
|
# fragment. Its default (`swarm-controller`) contains `swarm` and is caught
|
|
# by the substring guard whatever the cert-auth arm does — so a fixture using
|
|
# the default could not tell the two apart, and the arm under test would pass
|
|
# on the neighbour's work.
|
|
hiveNamedAfterCertSubject = hive {
|
|
deploy.swarm-otel.enable = false;
|
|
deploy.bao.controllerCommonName = "ctl";
|
|
swarm.hives.ctl.domain = "ctl.t.local";
|
|
};
|
|
|
|
# The control for both arms below: same shape, a roster nothing objects to.
|
|
hiveNamesAllLegal = hive {
|
|
deploy.swarm-otel.enable = false;
|
|
deploy.bao.controllerCommonName = "ctl";
|
|
};
|
|
|
|
# The reserved subjects are a LIST, and a list with one consulted element and
|
|
# one dead one looks identical from the first element's case. This fixture
|
|
# collides with the SECOND, leaving the controller's at its default.
|
|
hiveNamedAfterPublisherSubject = hive {
|
|
deploy.swarm-otel.enable = false;
|
|
deploy.bao.secretPublisherCommonName = "pubctl";
|
|
swarm.hives.pubctl.domain = "p.t.local";
|
|
};
|
|
|
|
# The THIRD element of the same list, colliding on its own so neither of the
|
|
# two above can carry it. matrix-ctl's grant is one path rather than a whole
|
|
# prefix, which is exactly why a dead entry here would be easy to miss: a
|
|
# hive that inherited it would not obviously break anything, it would
|
|
# silently gain the ability to overwrite the swarm's matrix credential.
|
|
hiveNamedAfterMatrixCtlSubject = hive {
|
|
deploy.swarm-otel.enable = false;
|
|
deploy.bao.matrixCtlCommonName = "mintctl";
|
|
swarm.hives.mintctl.domain = "m.t.local";
|
|
};
|
|
|
|
hiveNameWithComposedWord = hive {
|
|
deploy.swarm-otel.enable = false;
|
|
swarm.hives."h1-agent".domain = "a.t.local";
|
|
};
|
|
|
|
# Markers from `lib/name-guards.nix`'s two `problem` strings. Matching the
|
|
# problem rather than the `why` prose keeps the messages rewordable.
|
|
equalityGuardFired =
|
|
h: lib.any (a: !a.assertion && lib.hasInfix "has reserved name(s)" a.message) h.assertions;
|
|
|
|
fragmentGuardFired =
|
|
h:
|
|
lib.any (
|
|
a: !a.assertion && lib.hasInfix "has name(s) containing a reserved word" a.message
|
|
) h.assertions;
|
|
cases = [
|
|
{
|
|
# `ctl` is in no deny list — it is reserved *because it is the subject a
|
|
# cert-auth role accepts*, which is a value an operator sets, so a
|
|
# literal deny entry could never have covered it.
|
|
name = "a hive named after a cert-auth subject is refused, with the collector off";
|
|
ok =
|
|
equalityGuardFired hiveNamedAfterCertSubject
|
|
&& lib.any (a: !a.assertion && lib.hasInfix "'ctl'" a.message) hiveNamedAfterCertSubject.assertions;
|
|
}
|
|
{
|
|
# Every cert-auth subject is reserved, not just the first one in the
|
|
# list. Without this case the second element could be dead and the case
|
|
# above would still pass.
|
|
name = "a hive named after the secret publisher's subject is refused too";
|
|
ok =
|
|
equalityGuardFired hiveNamedAfterPublisherSubject
|
|
&& lib.any (
|
|
a: !a.assertion && lib.hasInfix "'pubctl'" a.message
|
|
) hiveNamedAfterPublisherSubject.assertions;
|
|
}
|
|
{
|
|
# And the third, for the reason the second one's comment gives one list
|
|
# element earlier. `certAuthCns` is where a role added beside the others
|
|
# has to register itself, and nothing but a case per element notices when
|
|
# one forgets.
|
|
name = "a hive named after matrix-ctl's subject is refused too";
|
|
ok =
|
|
equalityGuardFired hiveNamedAfterMatrixCtlSubject
|
|
&& lib.any (
|
|
a: !a.assertion && lib.hasInfix "'mintctl'" a.message
|
|
) hiveNamedAfterMatrixCtlSubject.assertions;
|
|
}
|
|
{
|
|
# Without this the case above proves nothing: an arm that fires for every
|
|
# roster is not a guard, and `hives` is non-empty in both fixtures.
|
|
name = "a legal hive roster trips neither name guard";
|
|
ok = !(equalityGuardFired hiveNamesAllLegal) && !(fragmentGuardFired hiveNamesAllLegal);
|
|
}
|
|
{
|
|
# The substring guard came along in the move and has to still work.
|
|
# `h1-agent` mints exactly the client id hive `h1`'s agents present.
|
|
name = "a hive name containing a composed-identifier word is refused, with the collector off";
|
|
ok = fragmentGuardFired hiveNameWithComposedWord;
|
|
}
|
|
{
|
|
# ⚠️ The control that makes "with the collector off" mean anything. If a
|
|
# fixture silently had swarm-otel enabled, all three cases above would
|
|
# pass while testing the arrangement they exist to rule out.
|
|
name = "the guard fixtures really do have the collector disabled";
|
|
ok =
|
|
!hiveNamedAfterCertSubject.services.hyperhive.deploy.swarm-otel.enable
|
|
&& !hiveNamesAllLegal.services.hyperhive.deploy.swarm-otel.enable
|
|
&& !hiveNameWithComposedWord.services.hyperhive.deploy.swarm-otel.enable;
|
|
}
|
|
];
|
|
in
|
|
runGroup "name-guards" cases
|