diff --git a/docs/swarm/services.md b/docs/swarm/services.md index 24efda7b..e16aa6eb 100644 --- a/docs/swarm/services.md +++ b/docs/swarm/services.md @@ -132,9 +132,10 @@ the collector is the only intended writer. ### Logs (VictoriaLogs) -The swarm's service containers ship their journals to one VictoriaLogs at -`logs.`, behind the same SSO as everything else. The -collector below is what writes to it. +Each hive ships its journals to one VictoriaLogs at `logs.`, +behind the same SSO as everything else: the swarm's own service containers, +the hive's daemons and infra containers, and the harness units inside every +agent container. The collector below is what writes to it. **Reading them.** Open Grafana, pick **Explore**, and choose the `VictoriaLogs` datasource — it is provisioned for you. Grafana's *Logs diff --git a/nix/host-modules/hive-c0re/default.nix b/nix/host-modules/hive-c0re/default.nix index 2d534249..a94a73bb 100644 --- a/nix/host-modules/hive-c0re/default.nix +++ b/nix/host-modules/hive-c0re/default.nix @@ -139,9 +139,21 @@ in # The daemon that owns every container on this hive, and the helper it # delegates its root operations to. An agent asking why a container did # not come up is asking about one of these two. + # + # The four agent-side units are named here rather than by the + # `agent-modules/` that define them, which is the one case where "a + # module names its own units" cannot hold: those modules are evaluated + # inside the guest, and this option belongs to the host. This module is + # the host's only knowledge that agent containers exist at all. They are + # also exactly the units the dashboard offers as journal filters, so + # without them the store cannot answer a question the UI can ask. services.hyperhive.swarm.otel.journaldUnits = [ "hive-c0re" "hive-priv" + "hive-agent" + "hive-mcp-http" + "hive-bash-daemon" + "hive-matrix-daemon" ]; assertions = [ diff --git a/nix/host-modules/hive-ci.nix b/nix/host-modules/hive-ci.nix index ef316a5b..a77a83a6 100644 --- a/nix/host-modules/hive-ci.nix +++ b/nix/host-modules/hive-ci.nix @@ -176,6 +176,11 @@ in } ]; + # The runner's journal, named as the unit is *inside* the container — + # nixpkgs derives `gitea-runner-` from the attr below, so this + # name follows that attr rather than `cfg.name`. + services.hyperhive.swarm.otel.journaldUnits = [ "gitea-runner-hive" ]; + # Create /run/hive-ci/ on the host and seed runner-token with a # placeholder. The container bind-mounts this file read-only; hive-c0re # (via hive-priv's RegisterCiRunner) overwrites it with the real diff --git a/nix/host-modules/hive-matrix.nix b/nix/host-modules/hive-matrix.nix index 002dcb18..98b4ce6d 100644 --- a/nix/host-modules/hive-matrix.nix +++ b/nix/host-modules/hive-matrix.nix @@ -501,6 +501,16 @@ in # every clause below carries that guard. services.hyperhive.gateway.localNames = lib.optional (cfg.gatewayHost != null) cfg.gatewayHost; + # The homeserver's own journal (`tuwunel` is the unit name inside the + # container, whatever the nixpkgs option is called), plus the host-side + # oneshot that mints its OIDC secret — carrying the same `ssoLocal` + # guard the unit itself is declared under, so the list never names a + # unit this deployment does not define. + services.hyperhive.swarm.otel.journaldUnits = [ + "tuwunel" + ] + ++ lib.optional ssoLocal "hive-matrix-oidc-secret"; + # This swarm-ui quick-links entry. Gated on `gui.enable` too, not just # `gatewayHost != null`: `/` on that vhost only serves fluffychat # (below) when the GUI is on — otherwise the link would 404, the same