diff --git a/hive-c0re/src/auto_update.rs b/hive-c0re/src/auto_update.rs index af2cb95f..db81b452 100644 --- a/hive-c0re/src/auto_update.rs +++ b/hive-c0re/src/auto_update.rs @@ -164,16 +164,17 @@ pub async fn rebuild_agent( result } -/// Whether hive-c0re auto-manages the root/manager agent — creating it on -/// startup and restarting it when present-but-stopped. Controlled by the -/// host option `services.hyperhive.manageRootAgent`, threaded in via the -/// `HYPERHIVE_MANAGE_ROOT_AGENT` env var. Defaults to enabled when the -/// var is unset (back-compat: the root agent was always managed before -/// this opt-out existed); only an explicit `false` / `0` / `no` disables. -fn manage_root_agent() -> bool { - match std::env::var("HYPERHIVE_MANAGE_ROOT_AGENT") { - Ok(v) => !matches!(v.trim().to_ascii_lowercase().as_str(), "false" | "0" | "no"), - Err(_) => true, +/// Whether this hive is "ruthless" — running with no root/manager agent at +/// all (no ruth). When true, hive-c0re skips the root-agent create/start +/// sweep entirely. Controlled by the host option +/// `services.hyperhive.ruthless`, threaded in via the `HYPERHIVE_RUTHLESS` +/// env var. Defaults to `false` when the var is unset (back-compat: the +/// root agent was always auto-managed before this opt-out existed); only +/// an explicit `true` / `1` / `yes` enables ruthless mode. +fn ruthless() -> bool { + match std::env::var("HYPERHIVE_RUTHLESS") { + Ok(v) => matches!(v.trim().to_ascii_lowercase().as_str(), "true" | "1" | "yes"), + Err(_) => false, } } @@ -181,13 +182,12 @@ fn manage_root_agent() -> bool { /// hive-c0re manages the manager end-to-end: operators no longer declare /// `containers.h-ruth` in their host NixOS config. Bypasses the approval /// queue — the root/manager is auto-managed by default. Operators who -/// don't want a root agent at all set `services.hyperhive.manageRootAgent -/// = false`, which short-circuits this whole function. Idempotent. +/// don't want a root agent at all set `services.hyperhive.ruthless = true`, +/// which short-circuits this whole function. Idempotent. pub async fn ensure_root_agent(coord: &Arc) -> Result<()> { - if !manage_root_agent() { + if ruthless() { tracing::info!( - "root-agent auto-management disabled (services.hyperhive.manageRootAgent = false) - \ - skipping root agent create/start" + "ruthless mode (services.hyperhive.ruthless = true) - skipping root agent create/start" ); return Ok(()); } @@ -224,7 +224,7 @@ pub async fn ensure_root_agent(coord: &Arc) -> Result<()> { // stays down until a manual `nixos-container start`. The sub-agent // `was_running` guard is intentionally left untouched. (Operators // opt out of this whole auto-management with - // `services.hyperhive.manageRootAgent = false`, gated at the top of + // `services.hyperhive.ruthless = true`, gated at the top of // this function.) if !lifecycle::is_running(MANAGER_NAME).await { tracing::info!("manager container present but not running — starting"); diff --git a/nix/modules/hive-c0re.nix b/nix/modules/hive-c0re.nix index 2791d7a6..5bf0af7c 100644 --- a/nix/modules/hive-c0re.nix +++ b/nix/modules/hive-c0re.nix @@ -187,22 +187,22 @@ in ''; }; - # Whether hive-c0re auto-manages the root/manager agent on startup - # (create it if missing, restart it if present-but-stopped). Some hives - # don't want a root agent auto-managed at all — see issue tracker - # "scope concept: special agents". - options.services.hyperhive.manageRootAgent = lib.mkOption { + # Whether this hive runs "ruthless" — with no root/manager agent at all. + # When true, hive-c0re skips the root-agent auto-management sweep (create + # if missing, restart if present-but-stopped). Some hives don't want a + # root agent at all — see issue tracker "scope concept: special agents". + options.services.hyperhive.ruthless = lib.mkOption { type = lib.types.bool; - default = true; - example = false; + default = false; + example = true; description = '' - Whether hive-c0re auto-manages the root (manager) agent on - startup: creating its container when missing and restarting it - when it's present but stopped. Defaults to `true` (the historical - behaviour — the root agent was treated as required infrastructure). - Set to `false` on hives that don't want a root agent at all; - hive-c0re then skips the root-agent create/start sweep entirely. - Exposed to hive-c0re as `HYPERHIVE_MANAGE_ROOT_AGENT`. + Run this hive "ruthless" — with no root (manager) agent at all (no + ruth). When `true`, hive-c0re skips the root-agent auto-management + sweep entirely (it otherwise creates the root agent's container when + missing and restarts it when present but stopped). Defaults to + `false` (the historical behaviour — the root agent is auto-managed + as required infrastructure). Exposed to hive-c0re as + `HYPERHIVE_RUTHLESS`. ''; }; @@ -892,10 +892,10 @@ in # prompts). `hive_sh4re::assets::*` reads paths underneath. # `forge.rs` reads the avatar PNGs from here on startup. HIVE_ASSETS_DIR = "${cfg.assets}/share/hyperhive"; - # Whether hive-c0re auto-manages the root/manager agent on - # startup (`auto_update::ensure_root_agent`). Default true = - # historical behaviour; false makes the root-agent sweep a no-op. - HYPERHIVE_MANAGE_ROOT_AGENT = lib.boolToString config.services.hyperhive.manageRootAgent; + # Whether this hive runs ruthless — no root/manager agent at all + # (`auto_update::ensure_root_agent`). Default false = historical + # behaviour (root auto-managed); true makes the sweep a no-op. + HYPERHIVE_RUTHLESS = lib.boolToString config.services.hyperhive.ruthless; } // lib.optionalAttrs (config.services.hyperhive.domain != null) { # Identity env vars threaded into c0re's own service env and