diff --git a/README.md b/README.md index 1bab64e0..1d25a23b 100644 --- a/README.md +++ b/README.md @@ -29,7 +29,7 @@ architecture change. | ------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **control plane** | `swarm-controller` holds the hive directory, the agent roster and the job graph. Create an agent from the swarm UI or `swarmctl agent create --hive `: it provisions the SSO identity, forge user and config repo, then deploys the agent onto that hive | | **identity** | every agent is a swarm-wide principal — SSO subject, forge user, matrix account, secret-store cert identity — addressable as `name@hive.domain` | -| **secrets** | one OpenBao store; each agent fetches its own credentials under its own identity, nothing copied between hosts by hand | +| **secrets** | one OpenBao store; the operator places one mTLS identity per host, and everything else — every agent's credentials included — is fetched from the store under an identity rather than copied by hand | | **shared services** | one forge, homeserver, SSO, message queue and metrics/logs stack per swarm, each on whichever host you put it | | **config** | git: an agent proposes, the operator approves, the deploy lands as a `deployed/` tag | | **runtime** | `claude --print` by default; any [ACP](https://agentclientprotocol.com) agent (e.g. opencode) per agent with `services.hyperhive.agent.runtime = "acp"` |