Watch
0
0
Fork
You've already forked hyperhive
0

docs(turn-loop): move harness systemd unit shape out of agent-roster.md

Moves the "Harness systemd unit shape" section from
docs/agent-lifecycle/agent-roster.md into docs/turn-loop/README.md: it
describes the per-agent harness systemd unit (env vars, PATH wiring,
serviceConfig), which is turn-loop material, not roster material.

Fixes two facts while moving: the ExecStart package is `hive-agent`,
not `hyperhive` (no package by that name exists); and `ruth.nix`
doesn't set any forge subscription default — it only defaults
`services.hyperhive.agent.docs.enable`.

Updates the inbound pointers in docs/turn-loop/config.md and the
module comment at nix/agent-modules/agent-service.nix.

Refs #3902
This commit is contained in:
atlas 2026-10-02 12:59:40 +02:00 • committed by mara
commit 2b2608a491
4 changed files with 75 additions and 68 deletions

View file

@ -57,10 +57,13 @@ Set to `false` for agents that should be strictly unprivileged.
Any tool invocation that needs root then fails loudly with the standard
sudo rejection rather than silently succeeding — easier to audit.
`services.hyperhive.agent.user.uid`, `services.hyperhive.agent.user.gid`, and
`services.hyperhive.agent.user.name` are the companion options; see
`docs/agent-lifecycle/agent-roster.md` — "Harness systemd unit shape" for the full
`user.*` surface.
`services.hyperhive.agent.user.name` is the unix user the harness and
its co-process daemons run as inside the container (default `"agent"`
for a standalone evaluation; the meta flake rebinds it to the agent's
own name). `services.hyperhive.agent.user.uid` / `.gid` are optional
fixed UID/GID (`null` default lets NixOS assign one automatically from
the normal-user range) — set them only when something outside the
container needs a stable numeric id across a full destroy + recreate.
## Dashboard links