Prose-only sweep of every remaining claim that nginx or dnsmasq lives in a container: the port comment (root in a container -> root on the host), upstreamHost's netns rationale, the ACME state dir, the store path reachability note, the vhost tree header, dnsmasq's resolv.conf paragraph (there is no copy and no path unit watching it any more), the two hive-network bridge comments, and swarm-controller's socket access-control note, which described a bind-mount that no longer exists. No behaviour change; all of it was describing a mechanism that was deleted.
82 lines
3.9 KiB
Nix
82 lines
3.9 KiB
Nix
# Hive-internal DNS resolver + DHCP, running on the host alongside the
|
|
# gateway's nginx — single front-door for both DNS and HTTP, and no
|
|
# container of its own. Listens on the bridge interface from
|
|
# `services.hyperhive.network`; authoritative for the hive domain +
|
|
# sub-domains, forwards everything else upstream. Returns the
|
|
# `services.dnsmasq` value (see ./default.nix); the DHCP pool bounds
|
|
# are computed by hive-network.
|
|
{
|
|
lib,
|
|
networkCfg,
|
|
forgeCfg,
|
|
matrixCfg,
|
|
autheliaCfg,
|
|
hyperhiveDomain,
|
|
}:
|
|
{
|
|
enable = true;
|
|
# Don't substitute the container's /etc/resolv.conf — the gateway
|
|
# uses the host's resolver for its own outbound traffic; dnsmasq is
|
|
# purely for incoming queries from agent containers.
|
|
resolveLocalQueries = false;
|
|
settings = {
|
|
# Bind only on the bridge interface (and lo for health-checks).
|
|
# Outside hosts can't even see the listener.
|
|
interface = [
|
|
networkCfg.bridgeName
|
|
"lo"
|
|
];
|
|
bind-interfaces = true;
|
|
port = 53;
|
|
# Authoritative for the hive domain via the `address` rules below —
|
|
# must not fall back to the host's /etc/hosts. dnsmasq reads
|
|
# /etc/hosts by default, and `gateway.localHostsEntry` populates it
|
|
# with 127.0.0.1 for every hive name (host-side dev convenience,
|
|
# see default.nix). Since moving dnsmasq onto the host, that
|
|
# file is now the *same* /etc/hosts dnsmasq reads for agent queries
|
|
# — its entries win over `address=`, so every agent resolves the
|
|
# hive's own domains back to itself (127.0.0.1 in its own netns)
|
|
# instead of the bridge IP, and can't reach the forge, matrix, or
|
|
# dashboard at all. `no-hosts = true` keeps the authoritative
|
|
# `address=` rules in charge for containers while leaving
|
|
# `networking.hosts` (the actual /etc/hosts entries) untouched for
|
|
# host-side browsing.
|
|
no-hosts = true;
|
|
# Hive authoritative records — answer queries for the hive domain
|
|
# + its sub-domains with the bridge IP, where nginx is reachable
|
|
# from every container netns.
|
|
#
|
|
# The forge / matrix entries are redundant in the common case
|
|
# where `forge.domain` / `matrix.gatewayHost` are sub-domains of
|
|
# `hyperhive.domain` — dnsmasq's `/<domain>/` rule already matches
|
|
# sub-domains. Kept explicit because operators can override either
|
|
# to a cross-domain hostname (e.g. `forge.domain =
|
|
# "git.example.com"`); listing them explicitly keeps that case
|
|
# routed without needing an extra config block.
|
|
address = [
|
|
"/${hyperhiveDomain}/${networkCfg.bridgeIp}"
|
|
]
|
|
++ lib.optional ((forgeCfg.behindGateway or false)) "/${forgeCfg.domain}/${networkCfg.bridgeIp}"
|
|
++ lib.optional (
|
|
matrixCfg.enable && matrixCfg.gatewayHost != null
|
|
) "/${matrixCfg.gatewayHost}/${networkCfg.bridgeIp}"
|
|
++ lib.optional autheliaCfg.enable "/${autheliaCfg.domain}/${networkCfg.bridgeIp}";
|
|
# DHCP pool covering all usable host addresses on the bridge
|
|
# subnet — bounds computed by hive-network.nix from
|
|
# bridgeIp/bridgePrefixLength. All containers (agents and service
|
|
# containers such as hive-ci) receive their IPs dynamically.
|
|
dhcp-range = "${networkCfg.dhcpRangeStart},${networkCfg.dhcpRangeEnd},1h";
|
|
dhcp-leasefile = "/var/lib/dnsmasq/dnsmasq.leases";
|
|
# No explicit upstream: non-hive queries follow dnsmasq's
|
|
# resolv.conf default — the host's own `/etc/resolv.conf`, so the
|
|
# hive always uses the host's resolvers and follows them live. This
|
|
# used to be a *copy* nixos-container made at container start, kept
|
|
# fresh by a host-side path unit that pushed in a new one and
|
|
# reloaded dnsmasq; running on the host deleted both the copy and
|
|
# the machinery that watched it. Deliberately no fallback
|
|
# `server=`: dnsmasq queries
|
|
# all known upstreams in parallel, so a hardcoded public resolver
|
|
# would take a share of *normal* traffic, not just fill in when the
|
|
# host file is empty.
|
|
};
|
|
}
|