docs: state current behaviour without change-log wording
This commit is contained in:
parent
b83fdc60f3
commit
195cf75bbf
4 changed files with 14 additions and 18 deletions
|
|
@ -220,7 +220,7 @@ appearing; the sweep then overwrites the per-hive file, no boot
|
||||||
required.
|
required.
|
||||||
|
|
||||||
<!-- vale write-good.Passive = NO -->
|
<!-- vale write-good.Passive = NO -->
|
||||||
- **Room membership follows the account the sweep currently uses.**
|
- **Room membership is per account.**
|
||||||
`ensure_hive_space` takes the stored room id first: if a different
|
`ensure_hive_space` takes the stored room id first: if a different
|
||||||
account than the room's member created that id, the sweep's invite
|
account than the room's member created that id, the sweep's invite
|
||||||
comes back refused (a non-member can't invite), and the sweep logs it
|
comes back refused (a non-member can't invite), and the sweep logs it
|
||||||
|
|
@ -228,27 +228,25 @@ required.
|
||||||
operator-chosen: invite `@hive-<hive>:` into the existing Space and
|
operator-chosen: invite `@hive-<hive>:` into the existing Space and
|
||||||
chat room from a client, which keeps the history; or delete the
|
chat room from a client, which keeps the history; or delete the
|
||||||
hive's stored room-id files, after which the next sweep creates a
|
hive's stored room-id files, after which the next sweep creates a
|
||||||
Space and chat room owned by the current account and invites every
|
Space and chat room owned by the hive's sender account and invites every
|
||||||
agent into them. Leaving it unresolved gives a hive that provisions
|
agent into them. Leaving it unresolved gives a hive that provisions
|
||||||
no rooms.
|
no rooms.
|
||||||
<!-- vale write-good.Passive = YES -->
|
<!-- vale write-good.Passive = YES -->
|
||||||
|
|
||||||
</details>
|
</details>
|
||||||
|
|
||||||
<details><summary>Appservice identity, not the registration token</summary>
|
<details><summary>Appservice identity</summary>
|
||||||
|
|
||||||
The activation script mints the appservice token and renders the
|
The activation script mints the appservice token and renders the
|
||||||
registration before the homeserver restarts, so every boot has both
|
registration before the homeserver restarts, so every boot has both
|
||||||
halves. `registrationTokenFile` is a removed option: a config that
|
halves.
|
||||||
still sets it fails to evaluate with a message naming the appservice.
|
|
||||||
|
|
||||||
<!-- vale write-good.Passive = NO -->
|
<!-- vale write-good.Passive = NO -->
|
||||||
- **Access tokens live on the device that minted them.**
|
- **Access tokens live on the device that minted them.**
|
||||||
`login_with_password` stays on, so the password fallback works
|
`login_with_password` stays on, so the password fallback works
|
||||||
too.
|
too.
|
||||||
- **The homeserver's `admin_execute` promotes only `@swarm` at boot**
|
- **The homeserver's `admin_execute` promotes only `@swarm` at boot**
|
||||||
(above); a hive's sender account is never promoted, regardless of
|
(above); a hive's sender account is never promoted.
|
||||||
when it was created.
|
|
||||||
- **The value that matters lives at `matrix/appservice-token`.**
|
- **The value that matters lives at `matrix/appservice-token`.**
|
||||||
`swarm-secret-publish` on the authelia host mints and `put`s it
|
`swarm-secret-publish` on the authelia host mints and `put`s it
|
||||||
there; the hive uses its locally minted token only until the first
|
there; the hive uses its locally minted token only until the first
|
||||||
|
|
|
||||||
|
|
@ -2,7 +2,7 @@
|
||||||
|
|
||||||
Every host's nginx: the one front door for whatever this host serves. A swarm service running here (forge, matrix, SSO, the swarm UI, the metrics and log stores) declares its own vhost through the gateway; the gateway itself adds the hive's own surface — dashboard, per-agent UIs, matrix discovery.
|
Every host's nginx: the one front door for whatever this host serves. A swarm service running here (forge, matrix, SSO, the swarm UI, the metrics and log stores) declares its own vhost through the gateway; the gateway itself adds the hive's own surface — dashboard, per-agent UIs, matrix discovery.
|
||||||
|
|
||||||
_For the operator configuring `services.hyperhive.gateway.*` on a host._ nginx and the hive resolver (dnsmasq) run on the host next to hive-c0re, not in a container: they bind `:80`/`:443` and the bridge address.
|
_For the operator configuring `services.hyperhive.gateway.*` on a host._ nginx and the hive resolver (dnsmasq) run on the host next to hive-c0re: they bind `:80`/`:443` and the bridge address.
|
||||||
|
|
||||||
You rarely switch it on yourself. `gateway.enable` defaults to off, and every module that serves a vhost or needs hive names to resolve sets `gateway.enable` / `gateway.dns.enable` with `mkDefault true` — the hive controller, each swarm service, CI.
|
You rarely switch it on yourself. `gateway.enable` defaults to off, and every module that serves a vhost or needs hive names to resolve sets `gateway.enable` / `gateway.dns.enable` with `mkDefault true` — the hive controller, each swarm service, CI.
|
||||||
|
|
||||||
|
|
@ -29,7 +29,7 @@ You rarely switch it on yourself. `gateway.enable` defaults to off, and every mo
|
||||||
| `<hive>/api/docs/` | themed Swagger UI dist (static) | always |
|
| `<hive>/api/docs/` | themed Swagger UI dist (static) | always |
|
||||||
| `<hive>/agent/<name>/` | per-agent harness over its unix socket | `agents.conf` (runtime-generated) |
|
| `<hive>/agent/<name>/` | per-agent harness over its unix socket | `agents.conf` (runtime-generated) |
|
||||||
| `<hive>/.well-known/matrix/{client,server}` | inline JSON | `deploy.matrix.enable` |
|
| `<hive>/.well-known/matrix/{client,server}` | inline JSON | `deploy.matrix.enable` |
|
||||||
| `<hive>/matrix/` (deprecated) | 301 → `chat.<swarm>/` | `deploy.matrix.gui.enable` and `gatewayHost` set |
|
| `<hive>/matrix/` | 301 → `chat.<swarm>/` | `deploy.matrix.gui.enable` and `gatewayHost` set |
|
||||||
|
|
||||||
The catch-all `_` vhost answers any other `Host` with `444` (connection closed, no response). It's `mkDefault`, so to make your own vhost the default server, set `services.nginx.virtualHosts."_".default = false;` — an eval assertion names both when two claim it.
|
The catch-all `_` vhost answers any other `Host` with `444` (connection closed, no response). It's `mkDefault`, so to make your own vhost the default server, set `services.nginx.virtualHosts."_".default = false;` — an eval assertion names both when two claim it.
|
||||||
|
|
||||||
|
|
@ -304,7 +304,7 @@ Every agent binds its web UI on a unix-domain socket at
|
||||||
`<dir>/hyperhive-socket-bound` next to the socket. c0re's
|
`<dir>/hyperhive-socket-bound` next to the socket. c0re's
|
||||||
`agent_sockets::write` filters its JSON map by marker presence —
|
`agent_sockets::write` filters its JSON map by marker presence —
|
||||||
only agents whose harness has bound the socket appear there.
|
only agents whose harness has bound the socket appear there.
|
||||||
It also accepts the older `.bound` name.
|
It also accepts `.bound`.
|
||||||
4. **Gateway side**. `gateway_nginx::write` generates
|
4. **Gateway side**. `gateway_nginx::write` generates
|
||||||
`/var/lib/hive-gateway/conf/agents.conf` — a plain nginx include
|
`/var/lib/hive-gateway/conf/agents.conf` — a plain nginx include
|
||||||
file with one `location /agent/<name>/` block per agent. Always
|
file with one `location /agent/<name>/` block per agent. Always
|
||||||
|
|
|
||||||
|
|
@ -26,9 +26,8 @@ Two ideas are all there is to it:
|
||||||
|
|
||||||
The engine's whole job is: whenever a step's ordering and resource needs
|
The engine's whole job is: whenever a step's ordering and resource needs
|
||||||
are both satisfied, run it. It has no opinion on what the steps _do_ —
|
are both satisfied, run it. It has no opinion on what the steps _do_ —
|
||||||
that's supplied by whoever builds the graph. The swarm controller and
|
that's supplied by whoever builds the graph. The engine is generic: the
|
||||||
hive-c0re each build their own graph on it, and nothing about the engine
|
swarm controller and hive-c0re each build their own graph on it.
|
||||||
is specific to either.
|
|
||||||
|
|
||||||
## Watching it happen
|
## Watching it happen
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -58,7 +58,7 @@ the control plane, so degraded telemetry isn't degraded operation.
|
||||||
|
|
||||||
### Why two tiers
|
### Why two tiers
|
||||||
|
|
||||||
**The hive tier isn't optional.** Exporting straight to `endpoint` would mean
|
**Agents export only to the hive tier.** Exporting straight to `endpoint` would mean
|
||||||
every agent needs the credential — and the only place to hand it to an agent
|
every agent needs the credential — and the only place to hand it to an agent
|
||||||
container is somewhere the agent itself can read, its own claude settings
|
container is somewhere the agent itself can read, its own claude settings
|
||||||
among them. `0600` protects a secret from other containers, not from the
|
among them. `0600` protects a secret from other containers, not from the
|
||||||
|
|
@ -98,10 +98,9 @@ hive's collector can label its data as any other agent.
|
||||||
**Logs ride the same hop, and a journal carries more than a counter does.** Each
|
**Logs ride the same hop, and a journal carries more than a counter does.** Each
|
||||||
agent container forwards its own journal through this port — every unit in it at
|
agent container forwards its own journal through this port — every unit in it at
|
||||||
`info` and above, not an allowlist. That's the harness, the MCP daemons and
|
`info` and above, not an allowlist. That's the harness, the MCP daemons and
|
||||||
whatever a tool call spawned, so command lines and error text now leave the
|
whatever a tool call spawned, so command lines and error text leave the
|
||||||
container, not just counts. The trust boundary is unchanged (same
|
container, not just counts. Destination, credential and trust boundary are the
|
||||||
destination, same credential, and an agent could already send arbitrary OTLP);
|
same as for any OTLP the agent sends.
|
||||||
what changes is how much detail leaves by default.
|
|
||||||
|
|
||||||
<!-- vale write-good.Passive = YES -->
|
<!-- vale write-good.Passive = YES -->
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue