fleet.nix

 1# Fleet-wide checks on every host, whatever its layout.
 2#
 3#   fleet.roles   the host's roles from hosts.json (set by hive.nix)
 4#
 5# Exclusive roles must be alone on their host. A sovrn cell runs mail on
 6# 25/465/587/143/993, a catch-all :443 with on-demand TLS for tenant PDS
 7# hosts, and a per-host Stalwart plan; nothing else belongs behind that.
 8{ config, lib, ... }:
 9
10let
11  exclusive = [ "sovrn-cell" ];
12  roles = config.fleet.roles;
13in
14{
15  options.fleet.roles = lib.mkOption {
16    type = lib.types.listOf lib.types.str;
17    default = [ ];
18    description = "This host's roles, from hosts.json.";
19  };
20
21  config.assertions = map (role: {
22    assertion = !(lib.elem role roles) || roles == [ role ];
23    message = "role ${role} is exclusive, but this host also has: ${lib.concatStringsSep ", " (lib.remove role roles)}";
24  }) exclusive;
25}