fleet.nix
1# Fleet-wide checks on every host, whatever its layout.
2#
3# fleet.roles the host's roles from hosts.json (set by hive.nix)
4#
5# Exclusive roles must be alone on their host. A sovrn cell runs mail on
6# 25/465/587/143/993, a catch-all :443 with on-demand TLS for tenant PDS
7# hosts, and a per-host Stalwart plan; nothing else belongs behind that.
8{ config, lib, ... }:
9
10let
11 exclusive = [ "sovrn-cell" ];
12 roles = config.fleet.roles;
13in
14{
15 options.fleet.roles = lib.mkOption {
16 type = lib.types.listOf lib.types.str;
17 default = [ ];
18 description = "This host's roles, from hosts.json.";
19 };
20
21 config.assertions = map (role: {
22 assertion = !(lib.elem role roles) || roles == [ role ];
23 message = "role ${role} is exclusive, but this host also has: ${lib.concatStringsSep ", " (lib.remove role roles)}";
24 }) exclusive;
25}