The vault's claim makes a second provider of secret a second claimant, refused by name. The three uplink definitions declare uplink-networkmanager, uplink-systemd-networkd and uplink-dhcpcd, which the host reports for the manager it finds active, so the holder for a manager the machine does not run is refused the way any missing capability is. Merges after the controller holds the seat and the host reports the capability.
38 lines
2.4 KiB
JSON
38 lines
2.4 KiB
JSON
{
|
|
"module": "systemd-networkd",
|
|
"version": "1",
|
|
"capabilities": [
|
|
"package-manager",
|
|
"service-manager",
|
|
"uplink-systemd-networkd"
|
|
],
|
|
"claims": [
|
|
{
|
|
"name": "node-uplink",
|
|
"scope": "node"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "package",
|
|
"type": "package",
|
|
"package": "systemd"
|
|
},
|
|
{
|
|
"id": "config",
|
|
"type": "file",
|
|
"path": "/etc/systemd/network/00-mesh0.network",
|
|
"mode": "0644",
|
|
"content": "# Managed by the mesh (module systemd-networkd). Replaced on every push; edit\n# the catalogue instead.\n#\n# This machine's uplink is systemd-networkd's, and the mesh asks one thing of it\n# here (novox/hq ADR 0117): leave the private network's interface alone. mesh0\n# is the mesh's; the mesh brings it up and configures it itself. The mesh never\n# declares a link, an address, a route, a wireless network or its credentials,\n# nor a network file for any of this machine's own interfaces \u2014 those are\n# the operator's, and the link they make is the only channel the mesh reaches\n# this machine over.\n#\n# 00-: networkd applies the first .network file, in alphanumeric order across\n# every directory, that matches an interface, and ignores every later one even\n# if it matches too (systemd.network(5), [Match]). A catch-all of the operator's\n# \u2014 Name=*, Type=ether, a file with no [Match] at all \u2014 sorted before\n# this one would claim mesh0 first. 00 sorts before every numbered prefix the\n# man page recommends.\n#\n# Unmanaged=yes: \"no attempts are made to bring up or configure matching links,\n# equivalent to when there are no matching network files\" (systemd.network(5),\n# [Link], since 233). A match that ends the search, and does nothing else.\n#\n# No DNS setting, because none is needed: networkd never writes\n# /etc/resolv.conf. What it learns from a lease it hands only to\n# systemd-resolved, and the resolver file stays whatever resolv-conf wrote.\n# Whether resolved runs, and what it does with that, is the resolver\n# configuration's question, not the uplink's.\n#\n# The service is reloaded when this file changes, never restarted: a restart\n# drops the links networkd holds, this machine's channel to the mesh among them.\n[Match]\nName=mesh0\n\n[Link]\nUnmanaged=yes\n"
|
|
},
|
|
{
|
|
"id": "service",
|
|
"type": "service",
|
|
"unit": "systemd-networkd.service",
|
|
"reload-on": [
|
|
"config"
|
|
]
|
|
}
|
|
]
|
|
}
|