From 3a0f74c1e7efc9e8d852b5696a7babefd4edf736 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?m=C3=BCde?= Date: Thu, 1 Oct 2026 20:36:34 +0200 Subject: [PATCH] README: bao host mTLS identity is still placed by hand --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 1bab64e0..1d25a23b 100644 --- a/README.md +++ b/README.md @@ -29,7 +29,7 @@ architecture change. | ------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **control plane** | `swarm-controller` holds the hive directory, the agent roster and the job graph. Create an agent from the swarm UI or `swarmctl agent create --hive `: it provisions the SSO identity, forge user and config repo, then deploys the agent onto that hive | | **identity** | every agent is a swarm-wide principal — SSO subject, forge user, matrix account, secret-store cert identity — addressable as `name@hive.domain` | -| **secrets** | one OpenBao store; each agent fetches its own credentials under its own identity, nothing copied between hosts by hand | +| **secrets** | one OpenBao store; the operator places one mTLS identity per host, and everything else — every agent's credentials included — is fetched from the store under an identity rather than copied by hand | | **shared services** | one forge, homeserver, SSO, message queue and metrics/logs stack per swarm, each on whichever host you put it | | **config** | git: an agent proposes, the operator approves, the deploy lands as a `deployed/` tag | | **runtime** | `claude --print` by default; any [ACP](https://agentclientprotocol.com) agent (e.g. opencode) per agent with `services.hyperhive.agent.runtime = "acp"` |