diff --git a/docs/integrations/matrix.md b/docs/integrations/matrix.md index aad3babc..937198aa 100644 --- a/docs/integrations/matrix.md +++ b/docs/integrations/matrix.md @@ -220,7 +220,7 @@ appearing; the sweep then overwrites the per-hive file, no boot required. -- **Room membership follows the account the sweep currently uses.** +- **Room membership is per account.** `ensure_hive_space` takes the stored room id first: if a different account than the room's member created that id, the sweep's invite comes back refused (a non-member can't invite), and the sweep logs it @@ -228,27 +228,25 @@ required. operator-chosen: invite `@hive-:` into the existing Space and chat room from a client, which keeps the history; or delete the hive's stored room-id files, after which the next sweep creates a - Space and chat room owned by the current account and invites every + Space and chat room owned by the hive's sender account and invites every agent into them. Leaving it unresolved gives a hive that provisions no rooms. -
Appservice identity, not the registration token +
Appservice identity The activation script mints the appservice token and renders the registration before the homeserver restarts, so every boot has both -halves. `registrationTokenFile` is a removed option: a config that -still sets it fails to evaluate with a message naming the appservice. +halves. - **Access tokens live on the device that minted them.** `login_with_password` stays on, so the password fallback works too. - **The homeserver's `admin_execute` promotes only `@swarm` at boot** - (above); a hive's sender account is never promoted, regardless of - when it was created. + (above); a hive's sender account is never promoted. - **The value that matters lives at `matrix/appservice-token`.** `swarm-secret-publish` on the authelia host mints and `put`s it there; the hive uses its locally minted token only until the first diff --git a/docs/networking/gateway.md b/docs/networking/gateway.md index 8a9a3adf..802508f7 100644 --- a/docs/networking/gateway.md +++ b/docs/networking/gateway.md @@ -2,7 +2,7 @@ Every host's nginx: the one front door for whatever this host serves. A swarm service running here (forge, matrix, SSO, the swarm UI, the metrics and log stores) declares its own vhost through the gateway; the gateway itself adds the hive's own surface — dashboard, per-agent UIs, matrix discovery. -_For the operator configuring `services.hyperhive.gateway.*` on a host._ nginx and the hive resolver (dnsmasq) run on the host next to hive-c0re, not in a container: they bind `:80`/`:443` and the bridge address. +_For the operator configuring `services.hyperhive.gateway.*` on a host._ nginx and the hive resolver (dnsmasq) run on the host next to hive-c0re: they bind `:80`/`:443` and the bridge address. You rarely switch it on yourself. `gateway.enable` defaults to off, and every module that serves a vhost or needs hive names to resolve sets `gateway.enable` / `gateway.dns.enable` with `mkDefault true` — the hive controller, each swarm service, CI. @@ -29,7 +29,7 @@ You rarely switch it on yourself. `gateway.enable` defaults to off, and every mo | `/api/docs/` | themed Swagger UI dist (static) | always | | `/agent//` | per-agent harness over its unix socket | `agents.conf` (runtime-generated) | | `/.well-known/matrix/{client,server}` | inline JSON | `deploy.matrix.enable` | -| `/matrix/` (deprecated) | 301 → `chat./` | `deploy.matrix.gui.enable` and `gatewayHost` set | +| `/matrix/` | 301 → `chat./` | `deploy.matrix.gui.enable` and `gatewayHost` set | The catch-all `_` vhost answers any other `Host` with `444` (connection closed, no response). It's `mkDefault`, so to make your own vhost the default server, set `services.nginx.virtualHosts."_".default = false;` — an eval assertion names both when two claim it. @@ -304,7 +304,7 @@ Every agent binds its web UI on a unix-domain socket at `/hyperhive-socket-bound` next to the socket. c0re's `agent_sockets::write` filters its JSON map by marker presence — only agents whose harness has bound the socket appear there. - It also accepts the older `.bound` name. + It also accepts `.bound`. 4. **Gateway side**. `gateway_nginx::write` generates `/var/lib/hive-gateway/conf/agents.conf` — a plain nginx include file with one `location /agent//` block per agent. Always diff --git a/docs/scheduler/jobq.md b/docs/scheduler/jobq.md index 3bfafbe2..0bf926fc 100644 --- a/docs/scheduler/jobq.md +++ b/docs/scheduler/jobq.md @@ -26,9 +26,8 @@ Two ideas are all there is to it: The engine's whole job is: whenever a step's ordering and resource needs are both satisfied, run it. It has no opinion on what the steps _do_ — -that's supplied by whoever builds the graph. The swarm controller and -hive-c0re each build their own graph on it, and nothing about the engine -is specific to either. +that's supplied by whoever builds the graph. The engine is generic: the +swarm controller and hive-c0re each build their own graph on it. ## Watching it happen diff --git a/docs/scheduler/observability.md b/docs/scheduler/observability.md index 1825aa56..8711c3c5 100644 --- a/docs/scheduler/observability.md +++ b/docs/scheduler/observability.md @@ -58,7 +58,7 @@ the control plane, so degraded telemetry isn't degraded operation. ### Why two tiers -**The hive tier isn't optional.** Exporting straight to `endpoint` would mean +**Agents export only to the hive tier.** Exporting straight to `endpoint` would mean every agent needs the credential — and the only place to hand it to an agent container is somewhere the agent itself can read, its own claude settings among them. `0600` protects a secret from other containers, not from the @@ -98,10 +98,9 @@ hive's collector can label its data as any other agent. **Logs ride the same hop, and a journal carries more than a counter does.** Each agent container forwards its own journal through this port — every unit in it at `info` and above, not an allowlist. That's the harness, the MCP daemons and -whatever a tool call spawned, so command lines and error text now leave the -container, not just counts. The trust boundary is unchanged (same -destination, same credential, and an agent could already send arbitrary OTLP); -what changes is how much detail leaves by default. +whatever a tool call spawned, so command lines and error text leave the +container, not just counts. Destination, credential and trust boundary are the +same as for any OTLP the agent sends.