README: bao host mTLS identity is still placed by hand
This commit is contained in:
parent
eced5e0365
commit
3a0f74c1e7
1 changed files with 1 additions and 1 deletions
|
|
@ -29,7 +29,7 @@ architecture change.
|
||||||
| ------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
| ------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||||
| **control plane** | `swarm-controller` holds the hive directory, the agent roster and the job graph. Create an agent from the swarm UI or `swarmctl agent create --hive <h>`: it provisions the SSO identity, forge user and config repo, then deploys the agent onto that hive |
|
| **control plane** | `swarm-controller` holds the hive directory, the agent roster and the job graph. Create an agent from the swarm UI or `swarmctl agent create --hive <h>`: it provisions the SSO identity, forge user and config repo, then deploys the agent onto that hive |
|
||||||
| **identity** | every agent is a swarm-wide principal — SSO subject, forge user, matrix account, secret-store cert identity — addressable as `name@hive.domain` |
|
| **identity** | every agent is a swarm-wide principal — SSO subject, forge user, matrix account, secret-store cert identity — addressable as `name@hive.domain` |
|
||||||
| **secrets** | one OpenBao store; each agent fetches its own credentials under its own identity, nothing copied between hosts by hand |
|
| **secrets** | one OpenBao store; the operator places one mTLS identity per host, and everything else — every agent's credentials included — is fetched from the store under an identity rather than copied by hand |
|
||||||
| **shared services** | one forge, homeserver, SSO, message queue and metrics/logs stack per swarm, each on whichever host you put it |
|
| **shared services** | one forge, homeserver, SSO, message queue and metrics/logs stack per swarm, each on whichever host you put it |
|
||||||
| **config** | git: an agent proposes, the operator approves, the deploy lands as a `deployed/<id>` tag |
|
| **config** | git: an agent proposes, the operator approves, the deploy lands as a `deployed/<id>` tag |
|
||||||
| **runtime** | `claude --print` by default; any [ACP](https://agentclientprotocol.com) agent (e.g. opencode) per agent with `services.hyperhive.agent.runtime = "acp"` |
|
| **runtime** | `claude --print` by default; any [ACP](https://agentclientprotocol.com) agent (e.g. opencode) per agent with `services.hyperhive.agent.runtime = "acp"` |
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue