hyperhive/nix/host-modules/hive-gateway/dnsmasq.nix
atlas 030eef0948 refactor(3202): the swarm UI declares its own vhost and dns name
Last of the four. The vhost, its `auth_request` block and the swarm
apex's dns record move into swarm-ui.nix; vhosts.nix drops `uiCfg`,
`controllerCfg` and `autheliaCfg` and is now 259 lines of hive surface
with no swarm service in it.

Also collapses a THIRD copy of the per-service list. `networking.hosts`
restated every service's name with its own copy of that service's guard,
after the vhosts and the dnsmasq records had each done the same. It asks
the same question — which names does this host answer for — so it now
reads the same answer: a service added later lands in /etc/hosts with no
edit, and cannot land there under a different condition than it used for
DNS.

The `forceSSL`-not-`addSSL` comment travels intact: it records that
authelia answers an http auth subrequest with 400 and nginx's
auth_request only understands 2xx/401/403, so the scheme is load-bearing
for this vhost and no other.
2026-08-13 16:19:08 +02:00

83 lines
4 KiB
Nix

# Hive-internal DNS resolver + DHCP, running on the host alongside the
# gateway's nginx — single front-door for both DNS and HTTP, and no
# container of its own. Listens on the bridge interface from
# `services.hyperhive.network`; authoritative for the hive domain +
# sub-domains, forwards everything else upstream. Returns the
# `services.dnsmasq` value (see ./default.nix); the DHCP pool bounds
# are computed by hive-network.
{
lib,
cfg, # services.hyperhive.gateway
networkCfg,
hyperhiveDomain,
}:
{
enable = true;
# ON for its *plumbing*, not for the address it publishes.
#
# This flag does two separable things upstream. The one that matters
# here: it points dnsmasq's own upstream servers at a SEPARATE file
# (`resolv-file = /etc/dnsmasq-resolv.conf`, kept current by
# resolvconf). Without that, dnsmasq reads `/etc/resolv.conf` for its
# upstreams — so the moment the host's resolver is pointed at dnsmasq,
# every non-hive query goes in a circle.
#
# The other thing it does is publish `127.0.0.1` as the host's
# nameserver, which is the wrong address for this hive: see the
# `nameservers` override in ./default.nix, where the reason lives.
resolveLocalQueries = true;
settings = {
# Bind only on the bridge interface (and lo for health-checks).
# Outside hosts can't even see the listener.
interface = [
networkCfg.bridgeName
"lo"
];
bind-interfaces = true;
port = 53;
# Authoritative for the hive domain via the `address` rules below —
# must not fall back to the host's /etc/hosts. dnsmasq reads
# /etc/hosts by default, and `gateway.localHostsEntry` populates it
# with 127.0.0.1 for every hive name (host-side dev convenience,
# see default.nix). Since moving dnsmasq onto the host, that
# file is now the *same* /etc/hosts dnsmasq reads for agent queries
# — its entries win over `address=`, so every agent resolves the
# hive's own domains back to itself (127.0.0.1 in its own netns)
# instead of the bridge IP, and can't reach the forge, matrix, or
# dashboard at all. `no-hosts = true` keeps the authoritative
# `address=` rules in charge for containers while leaving
# `networking.hosts` (the actual /etc/hosts entries) untouched for
# host-side browsing.
no-hosts = true;
# Hive authoritative records — answer queries for the hive domain
# + its sub-domains with the bridge IP, where nginx is reachable
# from every container netns.
address = [
"/${hyperhiveDomain}/${networkCfg.bridgeIp}"
]
# Names contributed by the modules that own them
# (`gateway.localNames`). Same address as everything above — the
# bridge IP is the gateway's answer for anything it fronts, and a
# contributing module neither knows nor should know it.
#
# `unique` is not tidiness: two modules claiming one name would
# otherwise emit two `address=` rules for it, and dnsmasq resolves
# that by precedence rather than by complaining. An assertion in
# ./default.nix makes the collision loud instead.
++ map (name: "/${name}/${networkCfg.bridgeIp}") (lib.unique cfg.localNames);
# DHCP pool covering all usable host addresses on the bridge
# subnet — bounds computed by hive-network.nix from
# bridgeIp/bridgePrefixLength. All containers (agents and service
# containers such as hive-ci) receive their IPs dynamically.
dhcp-range = "${networkCfg.dhcpRangeStart},${networkCfg.dhcpRangeEnd},1h";
dhcp-leasefile = "/var/lib/dnsmasq/dnsmasq.leases";
# No explicit upstream: non-hive queries follow dnsmasq's
# resolv.conf default — the host's own `/etc/resolv.conf`, so the
# hive always uses the host's resolvers and follows them live with
# no copy to go stale. Deliberately no fallback
# `server=`: dnsmasq queries
# all known upstreams in parallel, so a hardcoded public resolver
# would take a share of *normal* traffic, not just fill in when the
# host file is empty.
};
}