Annotate the soauth network leaves instead of the networks map

SOC reported "Malformed config setting (docker.networks.soauth.range): Setting
name 'networks' conflicts with another similarly named setting" and refused to
render the config tree.

soc_docker.yaml annotated docker.networks itself, and every key in that block
was a scalar, so FlattenAnnotations registered docker.networks as a setting.
defaults.yaml holds a nested map there, so FlattenPillar separately registered
docker.networks.soauth.range, .gateway and .manager_only, and
HydrateAnnotations unions the two sets. The config tree gives each id segment
either a value or children, never both, so addToNode pushed docker.networks as
a childless leaf and then threw when docker.networks.soauth.range tried to
descend through it.

The annotations move down to the three leaves that actually carry values, so
docker.networks is a plain branch. This matches docker.containers, which is
nested the same way and has never carried annotations of its own.

docker.ulimits and the per-container networks list are unaffected: their pillar
values are lists rather than maps, so they stay single settings.
This commit is contained in:
Mike Reeves
2026-09-18 13:42:41 -04:00
parent 2e2f62f265
commit 6c0d4c15e8
+26 -9
View File
@@ -8,15 +8,32 @@ docker:
helpLink: docker
advanced: True
networks:
description: |
Docker networks used by the grid. sobridge carries most containers and takes its range and
gateway from the docker.range and docker.gateway settings above. soauth is an isolated
network for the authentication services, so that the Kratos admin and Hydra API is only reachable
from the containers placed on it.
helpLink: docker
readonly: True
advanced: True
global: True
soauth:
range:
description: |
IP range for the soauth docker network. soauth is an isolated network for the
authentication services, so that the Kratos and Hydra admin APIs are only reachable
from the containers placed on it. Most containers instead use sobridge, which takes
its range and gateway from the docker.range and docker.gateway settings above.
helpLink: docker
readonly: True
advanced: True
global: True
gateway:
description: Gateway for the soauth docker network.
helpLink: docker
readonly: True
advanced: True
global: True
manager_only:
description: |
Limits the soauth network to grid members running the authentication containers,
instead of creating it on every node.
helpLink: docker
readonly: True
advanced: True
global: True
forcedType: bool
ulimits:
description: |
Default ulimit settings applied to all containers via the Docker daemon. Each entry specifies a resource name (e.g. nofile, memlock, core, nproc) with soft and hard limits. Individual container ulimits override these defaults. Valid resource names include: cpu, fsize, data, stack, core, rss, nproc, nofile, memlock, as, locks, sigpending, msgqueue, nice, rtprio, rttime.