docs(boundary): update to reflect always-on network isolation

All three area:ops pillars are now complete: network isolation is
always on (private netns, no shared-netns mode), the gateway is live,
and hive-c0re runs as the unprivileged hive-core user.

- Rewrite the intro to say the boundary is enforced, not aspirational
- Update 'Why network isolation is the load-bearing step' section to
  use past tense for the shared-netns world and note completion
- Mark network isolation as Complete in the sequencing list
This commit is contained in:
atlas 2026-07-04 20:52:13 +02:00 committed by mara
commit 480b35aac4

View file

@ -5,11 +5,12 @@ _implementation_ work — container network isolation, the unifying
gateway, core-daemon privsep — is tracked as `area:ops` issues on gateway, core-daemon privsep — is tracked as `area:ops` issues on
the forge. the forge.
Today "the operator surface" and "the agent surface" are a The operator/agent boundary is now technically enforced, not just a
_convention_, not a boundary — nothing stops a container from convention. Containers run in private netns (network isolation is
curling the core daemon on `localhost:<port>`, or another agent's always on), the gateway proxies all operator-facing traffic, and
web UI. Network isolation, the gateway, and privsep together turn `hive-c0re` runs as the unprivileged `hive-core` user. All three
that convention into an enforced boundary. `area:ops` pillars — network isolation, the gateway, and privsep —
are complete and active.
## Two principals, two paths ## Two principals, two paths
@ -39,14 +40,17 @@ agent page).
## Why network isolation is the load-bearing step ## Why network isolation is the load-bearing step
Containers currently share the host network namespace, so a Without network isolation, containers share the host network namespace
container can reach `localhost:<core-port>`, the dashboard, and and can reach `localhost:<core-port>`, the dashboard, and every other
every other agent's web port. Until that changes, the agent's web port — the operator/agent split is on the honour system and
operator/agent split is on the honour system — every boundary every boundary claim above is aspirational. Network isolation is what
claim above is aspirational. Network isolation is what makes the makes the boundary _real_; the gateway and privsep are ergonomics and
boundary _real_; the gateway and privsep are ergonomics and
defence-in-depth layered on top. defence-in-depth layered on top.
Network isolation is now complete and always on: every agent container
runs in a private netns behind the hive bridge. The shared-netns mode
was removed. See `docs/network.md`.
The `area:ops` issues followed this sequencing: The `area:ops` issues followed this sequencing:
1. **Gateway** — pure ergonomics win, unblocks same-origin (lets the 1. **Gateway** — pure ergonomics win, unblocks same-origin (lets the
@ -54,7 +58,8 @@ The `area:ops` issues followed this sequencing:
behavioural risk. An nginx nixos-container now sits in front of all behavioural risk. An nginx nixos-container now sits in front of all
surfaces; per-agent UIs are proxied under `/agent/<name>/`. surfaces; per-agent UIs are proxied under `/agent/<name>/`.
2. **Network isolation** — the load-bearing step that turns the 2. **Network isolation** — the load-bearing step that turns the
honour-system split into an enforced boundary. In progress. honour-system split into an enforced boundary. **Complete**
always-on, unconditional; the shared-netns mode was removed.
3. **Privsep** — defence in depth on the core process; `hive-c0re` 3. **Privsep** — defence in depth on the core process; `hive-c0re`
runs as the unprivileged `hive-core` user and delegates root runs as the unprivileged `hive-core` user and delegates root
operations to `hive-priv`, a narrow socket-activated helper. See operations to `hive-priv`, a narrow socket-activated helper. See