docs(turn-loop): move harness systemd unit shape out of agent-roster.md
Moves the "Harness systemd unit shape" section from docs/agent-lifecycle/agent-roster.md into docs/turn-loop/README.md: it describes the per-agent harness systemd unit (env vars, PATH wiring, serviceConfig), which is turn-loop material, not roster material. Fixes two facts while moving: the ExecStart package is `hive-agent`, not `hyperhive` (no package by that name exists); and `ruth.nix` doesn't set any forge subscription default — it only defaults `services.hyperhive.agent.docs.enable`. Updates the inbound pointers in docs/turn-loop/config.md and the module comment at nix/agent-modules/agent-service.nix. Refs #3902
This commit is contained in:
parent
46f1f3cbdb
commit
2b2608a491
4 changed files with 75 additions and 68 deletions
|
|
@ -57,10 +57,13 @@ Set to `false` for agents that should be strictly unprivileged.
|
|||
Any tool invocation that needs root then fails loudly with the standard
|
||||
sudo rejection rather than silently succeeding — easier to audit.
|
||||
|
||||
`services.hyperhive.agent.user.uid`, `services.hyperhive.agent.user.gid`, and
|
||||
`services.hyperhive.agent.user.name` are the companion options; see
|
||||
`docs/agent-lifecycle/agent-roster.md` — "Harness systemd unit shape" for the full
|
||||
`user.*` surface.
|
||||
`services.hyperhive.agent.user.name` is the unix user the harness and
|
||||
its co-process daemons run as inside the container (default `"agent"`
|
||||
for a standalone evaluation; the meta flake rebinds it to the agent's
|
||||
own name). `services.hyperhive.agent.user.uid` / `.gid` are optional
|
||||
fixed UID/GID (`null` default lets NixOS assign one automatically from
|
||||
the normal-user range) — set them only when something outside the
|
||||
container needs a stable numeric id across a full destroy + recreate.
|
||||
|
||||
## Dashboard links
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue