Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

nixos/nomad: enforce specific data_dir semantics #109768

Merged
merged 12 commits into from Jan 24, 2021

Conversation

cpcloud
Copy link
Contributor

@cpcloud cpcloud commented Jan 18, 2021

Motivation for this change

This PR enforces the semantics discussed here: #105739 (comment)

In summary, the data_dir value of the nomad service must be set to
a specific value if dropPrivileges is set to true.

The updated unit also includes additional documentation describing
the responsibilities of the nomad cluster manager given these
constraints as well as a suggestion for how to go about satisfying them.

Things done
  • Tested using sandboxing (nix.useSandbox on NixOS, or option sandbox in nix.conf on non-NixOS linux)
  • Built on platform(s)
    • NixOS
    • macOS
    • other Linux distributions
  • Tested via one or more NixOS test(s) if existing and applicable for the change (look inside nixos/tests)
  • Tested compilation of all pkgs that depend on this change using nix-shell -p nixpkgs-review --run "nixpkgs-review wip"
  • Tested execution of all binary files (usually in ./result/bin/)
  • Determined the impact on package closure size (by running nix path-info -S before and after)
  • Ensured that relevant documentation is up to date
  • Fits CONTRIBUTING.md.

Copy link
Member

@aanderse aanderse left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Left a few thoughts. Ignore the StateDirectory comment... I read this commit by commit 😄

nixos/modules/services/networking/nomad.nix Outdated Show resolved Hide resolved
nixos/modules/services/networking/nomad.nix Outdated Show resolved Hide resolved
nixos/modules/services/networking/nomad.nix Outdated Show resolved Hide resolved
nixos/modules/services/networking/nomad.nix Outdated Show resolved Hide resolved
@cpcloud
Copy link
Contributor Author

cpcloud commented Jan 24, 2021

@aanderse Is this okay to merge?

Copy link
Member

@aanderse aanderse left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 👍

I'll defer to @lovesegfault for merge, preferably, though. I'm not a nomad user.

@cpcloud
Copy link
Contributor Author

cpcloud commented Jan 24, 2021

Roger that! Thanks.

@lovesegfault lovesegfault merged commit 105b9eb into NixOS:master Jan 24, 2021
@cpcloud cpcloud deleted the nomad-datadir-cleanup branch January 24, 2021 19:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants