feat(3088): move the gateway's nginx + dnsmasq onto the host

The gateway's nginx + dnsmasq no longer run in their own nspawn container.
`nix/host-modules/hive-gateway/default.nix` loses the
`containers.hive-gateway` wrapper and everything that existed only to punch
holes in it: `privateNetwork = false`, `CAP_NET_ADMIN`, five bind mounts,
its own `stateVersion`, `networking.firewall.enable = false`,
`networking.resolvconf.enable = false`, and the `hive-gateway-resolv`
path+service pair. 465 -> 303 lines.

The container never bought isolation here. It shared the host netns by
necessity — nginx binds the host's :80/:443, dnsmasq answers on the bridge —
so each of those settings was undoing a boundary the gateway could not
afford in the first place.

Four things made it more than a deletion, none of them visible in the nix
diff:

- The self-signed cert service also imports the hive CA leaf, so removing it
  with the container would have left nginx naming a missing cert file, which
  it refuses to load at all.
- The nginx reload is a hive-priv verb. It still needs root, but no longer
  for the reason its doc gave, and `--machine=` was both transport and
  scope — so the unit name is now hard-coded in the helper as the
  containment.
- The lifecycle verb named a container that stops existing.
- `journalctl -M hive-gateway` had no machine to enter.

Per the operator's ruling, the operator verb keeps working and agents lose
it. `InfraContainer` answered three questions that used to share an answer;
it now splits into `name()` (identity), `target()` (Container vs HostUnit),
`service_unit()` (the systemd unit), and `agent_restartable()`, which the
MCP restart path checks before the capability so the refusal cannot read as
"ask for infra_admin". `SIBLING_CONTAINERS` drops the gateway — it gates the
requests that name a container as a string — while `FromStr` still accepts
it, because that answers what a name is, not who may act on it. The
dashboard's gateway journal reads host journald filtered to `nginx.service`.

Prose was corrected where it only named a location, and re-argued where the
container was doing security work: a `0666` per-agent socket was safe
because only the gateway container had the directory bind-mounted. There is
no mount now, so the directory permissions are the whole of the access
control — the constraint holds, its mechanism doesn't.

Gate: nix fmt / clippy --all-targets -D warnings / cargo test all clean (710
tests); hivectl-cli.md regenerated from the clap tree. The nix eval was run
in both TLS shapes at this commit: every delta in the rendered
virtualHosts is one of the three intended path moves, dnsmasq settings are
byte-identical, and the absence probe flips true -> false with bindMounts
emptied.
This commit is contained in:
atlas 2026-08-11 18:00:27 +02:00
commit 07852cabc1
34 changed files with 704 additions and 618 deletions

View file

@ -1,9 +1,13 @@
//! Dashboard endpoint for operator-driven infra-container lifecycle
//! (start / stop / restart on `hive-ci`, `hive-forge`, `hive-gateway`,
//! `hive-matrix`). Parallels the `infra_admin`-gated agent path in
//! Dashboard endpoint for operator-driven infra lifecycle (start / stop /
//! restart on `hive-ci`, `hive-forge`, `hive-gateway`, `hive-matrix`).
//! Parallels the `infra_admin`-gated agent path in
//! `socket_server/lifecycle_handlers.rs::handle_restart_infra`, but this one
//! is reached from the dashboard — already fully operator-authenticated —
//! so no capability check is needed here, just the same audit trail.
//!
//! The two surfaces no longer cover the same set: the gateway is the
//! operator's to restart and not an agent's, since nginx on the host fronts
//! every hive service. This endpoint keeps all four.
use axum::{
extract::{Path as AxumPath, State},
@ -27,7 +31,7 @@ use super::{AppState, error_response};
post,
path = "/api/infra-container/{name}/{action}",
params(
("name" = String, Path, description = "infra container name (hive-ci/hive-forge/hive-gateway/hive-matrix)"),
("name" = String, Path, description = "infra service name (hive-ci/hive-forge/hive-gateway/hive-matrix)"),
("action" = String, Path, description = "start | stop | restart"),
),
responses(
@ -53,8 +57,8 @@ pub(super) async fn post_infra_container(
));
}
};
let unit = container.unit_name();
tracing::info!(%unit, %action, "dashboard: infra container action");
let target = container.name();
tracing::info!(%target, %action, "dashboard: infra container action");
let result = crate::priv_client::control_infra_container(container, infra_action).await;
let outcome = if result.is_ok() {
crate::audit_log::AuditOutcome::Ok
@ -66,12 +70,12 @@ pub(super) async fn post_infra_container(
state
.coord
.audit_log
.record("operator", action_label, unit, outcome, detail.as_deref())
.record("operator", action_label, target, outcome, detail.as_deref())
{
state.coord.emit_audit_entry(entry);
}
match result {
Ok(()) => (StatusCode::OK, "ok").into_response(),
Err(e) => error_response(&format!("{unit}: {e:#}")),
Err(e) => error_response(&format!("{target}: {e:#}")),
}
}

View file

@ -1,13 +1,15 @@
//! Journal-read endpoints for the dashboard.
//!
//! `GET /api/journal/{name}` reads a managed agent container's journal, OR
//! one of the four hive infra containers (`hive-ci`, `hive-forge`,
//! one of the four hive infra services (`hive-ci`, `hive-forge`,
//! `hive-gateway`, `hive-matrix` — [`hive_priv_sock::InfraContainer`] is the
//! allowlist), via the root helper (`journalctl -M`, delegated to hive-priv
//! since hive-c0re is unprivileged). `GET /api/journal-host` reads
//! host-side journald, both gated by an allow-list of known units so
//! arbitrary unit names can't be probed. Operator-only by virtue of the
//! dashboard binding host-only.
//! allowlist). A container's journal is a `journalctl -M` read, delegated
//! to the root helper since entering a machine needs privileges hive-c0re
//! doesn't have; `hive-gateway` is nginx on the host, so it reads host
//! journald filtered to that unit and needs no helper at all.
//! `GET /api/journal-host` reads host-side journald, both gated by an
//! allow-list of known units so arbitrary unit names can't be probed.
//! Operator-only by virtue of the dashboard binding host-only.
use axum::{
extract::Path as AxumPath,
@ -40,11 +42,12 @@ pub(super) struct JournalQuery {
/// container namespace and needs root — is delegated to hive-priv.
///
/// `name` is either a managed agent name (`iris`, optionally already
/// carrying the `h-` prefix) or one of the four infra container names
/// (`hive-ci` / `hive-forge` / `hive-gateway` / `hive-matrix` — see
/// [`hive_priv_sock::InfraContainer`]). Infra containers don't run the
/// per-agent hive daemons, so `unit` is ignored for them — always the
/// full machine journal.
/// carrying the `h-` prefix) or one of the four infra names (`hive-ci` /
/// `hive-forge` / `hive-gateway` / `hive-matrix` — see
/// [`hive_priv_sock::InfraContainer`]). Infra targets don't run the
/// per-agent hive daemons, so `unit` is ignored for them — the whole
/// machine journal, or for the gateway the host journal filtered to its
/// own unit.
#[utoipa::path(
get,
path = "/api/journal/{name}",
@ -66,7 +69,17 @@ pub(super) async fn get_journal(
let lines = q.lines.unwrap_or(500).min(5000);
if let Ok(infra) = name.parse::<hive_priv_sock::InfraContainer>() {
return read_journal_response(infra.unit_name(), None, lines).await;
return match infra.target() {
hive_priv_sock::InfraTarget::Container(machine) => {
read_journal_response(machine, None, lines).await
}
// No machine to enter — the gateway's nginx is a host unit, so
// this is a plain host-journal read filtered to it. `-M` is
// what needed root here, not journalctl itself.
hive_priv_sock::InfraTarget::HostUnit(unit) => {
read_host_journal_response(Some(unit), lines).await
}
};
}
// Defense-in-depth format check so weird chars never reach the
@ -180,21 +193,43 @@ pub(super) async fn get_journal_host(
axum::extract::Query(q): axum::extract::Query<JournalHostQuery>,
) -> Result<Response, ProblemDetails> {
let lines = q.lines.unwrap_or(500).min(5000);
let allowed = ["hive-c0re.service", "hive-priv.service"];
// `nginx.service` is the gateway: its logs used to live in the
// hive-gateway container's journal and are host-side now.
let allowed = ["hive-c0re.service", "hive-priv.service", "nginx.service"];
let unit = match q.unit.as_deref().filter(|s| !s.is_empty()) {
Some(u) => {
let unit = if u.ends_with(".service") {
u.to_owned()
} else {
format!("{u}.service")
};
if !allowed.contains(&unit.as_str()) {
return Err(ProblemDetails::from_status_code(StatusCode::BAD_REQUEST)
.with_detail(format!("journal-host: unknown unit {unit:?}")));
}
Some(unit)
}
None => None,
};
read_host_journal_response(unit.as_deref(), lines).await
}
/// `journalctl [-u <unit>]` on the host + response formatting. No `-M`, so
/// no root and no priv-client hop — hive-c0re reads host journald directly.
///
/// ⚠️ `unit` is trusted by the time it gets here: [`get_journal_host`]
/// allow-lists an operator-supplied one, and [`get_journal`] passes a unit
/// that came from the [`hive_priv_sock::InfraContainer`] enum. Don't hand
/// this a raw query parameter.
async fn read_host_journal_response(
unit: Option<&str>,
lines: u32,
) -> Result<Response, ProblemDetails> {
let mut cmd = tokio::process::Command::new("journalctl");
cmd.args(["--no-pager", "--output=short-iso", "--lines"])
.arg(lines.to_string());
if let Some(u) = q.unit.as_deref().filter(|s| !s.is_empty()) {
let unit = if u.ends_with(".service") {
u.to_owned()
} else {
format!("{u}.service")
};
if !allowed.contains(&unit.as_str()) {
return Err(ProblemDetails::from_status_code(StatusCode::BAD_REQUEST)
.with_detail(format!("journal-host: unknown unit {unit:?}")));
}
cmd.args(["-u", &unit]);
if let Some(u) = unit {
cmd.args(["-u", u]);
}
match cmd.output().await {
Ok(out) => {

View file

@ -154,7 +154,7 @@ async fn infra_container_views() -> Vec<InfraContainerView> {
let mut infra_containers = Vec::with_capacity(hive_priv_sock::InfraContainer::ALL.len());
for container in hive_priv_sock::InfraContainer::ALL {
infra_containers.push(InfraContainerView {
name: container.unit_name(),
name: container.name(),
running: crate::lifecycle::infra_is_running(container).await,
});
}