docs: name the matrix host options by their new path

Every prose and error-message reference to the moved options, including
two in hive-c0re/src/matrix.rs that omitted the services. prefix and so
read as the per-agent option. An error that names an option the operator
cannot find is worse than no hint.
This commit is contained in:
atlas 2026-08-05 10:57:19 +02:00 committed by mara
commit 5235166bb3
7 changed files with 17 additions and 15 deletions

View file

@ -3,7 +3,7 @@
Private Matrix homeserver (matrix-tuwunel — the conduwuit Private Matrix homeserver (matrix-tuwunel — the conduwuit
successor) wrapped in a nixos-container, plus optional fluffychat-web successor) wrapped in a nixos-container, plus optional fluffychat-web
client at `matrix.<hive>/`. Configured via client at `matrix.<hive>/`. Configured via
`services.hyperhive.matrix.*`; vhost routing lives in `services.hyperhive.swarm.matrix.*`; vhost routing lives in
[`gateway.md`](gateway.md). [`gateway.md`](gateway.md).
## Container shape ## Container shape
@ -60,7 +60,7 @@ client needs to reach the client-server API directly.
**Breaking change**: used to default to `true`. Operators relying on **Breaking change**: used to default to `true`. Operators relying on
external reach must add external reach must add
`services.hyperhive.matrix.openFirewall = true;` before rebuilding. `services.hyperhive.swarm.matrix.openFirewall = true;` before rebuilding.
Federation port 8448 is intentionally not opened here — tuwunel Federation port 8448 is intentionally not opened here — tuwunel
serves the federation API on the same `httpPort` as client-server serves the federation API on the same `httpPort` as client-server
@ -119,7 +119,7 @@ Initial rollout settings:
`yes_i_am_very_very_sure_…_open_registration_…` flag keeps the `yes_i_am_very_very_sure_…_open_registration_…` flag keeps the
server closed to anyone without the token. server closed to anyone without the token.
- `allow_encryption` — server-side E2EE switch, sourced from - `allow_encryption` — server-side E2EE switch, sourced from
`services.hyperhive.matrix.allowEncryption` (**default `false`**, opt-in). `services.hyperhive.swarm.matrix.allowEncryption` (**default `false`**, opt-in).
Off by default because on the hive-internal homeserver the operator Off by default because on the hive-internal homeserver the operator
already controls the transport; turn it on for encrypted rooms on already controls the transport; turn it on for encrypted rooms on
external / federated homeservers or to keep contents opaque to the external / federated homeservers or to keep contents opaque to the
@ -168,7 +168,7 @@ re-creation (e.g. after a homeserver wipe).
## Configuration tuning ## Configuration tuning
```nix ```nix
services.hyperhive.matrix = { services.hyperhive.swarm.matrix = {
trustedServers = [ "matrix.org" "example.com" ]; # default: [] trustedServers = [ "matrix.org" "example.com" ]; # default: []
maxRequestSize = 20000000; # default: 20 MB maxRequestSize = 20000000; # default: 20 MB
}; };

View file

@ -58,7 +58,7 @@ hivectl forge reconcile-config iris --verbose # include the full diff, not
Manual entry to the same idempotent matrix provisioning flow Manual entry to the same idempotent matrix provisioning flow
`hive-c0re` runs at boot. Requires the `hive-matrix` container to be `hive-c0re` runs at boot. Requires the `hive-matrix` container to be
running (`services.hyperhive.matrix.enable = true`). running (`services.hyperhive.swarm.matrix.enable = true`).
```bash ```bash
hivectl matrix create-user iris # provision (or re-provision) matrix account for agent `iris` hivectl matrix create-user iris # provision (or re-provision) matrix account for agent `iris`
@ -315,5 +315,5 @@ an error.
A surface has no URL when it isn't browser-reachable: `home` needs A surface has no URL when it isn't browser-reachable: `home` needs
`services.hyperhive.domain`; `forge` needs `services.hyperhive.domain`; `forge` needs
`services.hyperhive.forge.behindGateway = true`; `matrix` needs `services.hyperhive.forge.behindGateway = true`; `matrix` needs
`services.hyperhive.matrix.gui.enable = true`. In those cases the command `services.hyperhive.swarm.matrix.gui.enable = true`. In those cases the command
exits with a hint naming the option to set. exits with a hint naming the option to set.

View file

@ -679,9 +679,9 @@ existing in the page DOM.
A static matrix web client (default `pkgs.fluffychat-web` rebuilt A static matrix web client (default `pkgs.fluffychat-web` rebuilt
with `--base-href /matrix/`, swappable via with `--base-href /matrix/`, swappable via
`services.hyperhive.matrix.gui.package`) served by the hive-gateway `services.hyperhive.swarm.matrix.gui.package`) served by the hive-gateway
nginx container at `/matrix/` when nginx container at `/matrix/` when
`services.hyperhive.matrix.gui.enable` is on (defaults to `services.hyperhive.swarm.matrix.gui.enable` is on (defaults to
`matrix.enable`). c0re signals availability via the `matrix.enable`). c0re signals availability via the
`HIVE_MATRIX_GUI_ENABLED` env var → `state.matrix_gui_enabled` in `HIVE_MATRIX_GUI_ENABLED` env var → `state.matrix_gui_enabled` in
`/api/state`; the gateway does the actual static serving. `/api/state`; the gateway does the actual static serving.

View file

@ -84,7 +84,7 @@ pub(super) struct StateSnapshot {
forge_present: bool, forge_present: bool,
/// Whether the matrix GUI is reachable at `/matrix/`. Sourced from /// Whether the matrix GUI is reachable at `/matrix/`. Sourced from
/// `HIVE_MATRIX_GUI_ENABLED` env var (set by the c0re NixOS module /// `HIVE_MATRIX_GUI_ENABLED` env var (set by the c0re NixOS module
/// when `services.hyperhive.matrix.gui.enable` is on). The gateway /// when `services.hyperhive.swarm.matrix.gui.enable` is on). The gateway
/// (hive-gateway.nix) does the actual `/matrix/` static serving; /// (hive-gateway.nix) does the actual `/matrix/` static serving;
/// this flag is just an availability signal for iris's dashboard /// this flag is just an availability signal for iris's dashboard
/// chrome so the `M4TR1X →` tab doesn't flash when the GUI is off. /// chrome so the `M4TR1X →` tab doesn't flash when the GUI is off.

View file

@ -1,7 +1,8 @@
//! Optional matrix-tuwunel wiring: shared registration token (host) + //! Optional matrix-tuwunel wiring: shared registration token (host) +
//! per-agent UIAA registration → `<agent-state>/matrix-token`. No-op //! per-agent UIAA registration → `<agent-state>/matrix-token`. No-op
//! when the `hive-matrix` container isn't running, so operators who //! when the `hive-matrix` container isn't running, so operators who
//! haven't flipped `hyperhive.matrix.enable = true` pay nothing. //! haven't flipped `services.hyperhive.swarm.matrix.enable = true` pay
//! nothing.
//! //!
//! See `docs/matrix.md::Provisioning flow (registration token)` for //! See `docs/matrix.md::Provisioning flow (registration token)` for
//! the full UIAA round-trip, token-file shape, and host/container //! the full UIAA round-trip, token-file shape, and host/container
@ -16,7 +17,7 @@ use crate::coordinator::Coordinator;
/// Client-server API base this daemon provisions against, from /// Client-server API base this daemon provisions against, from
/// `HIVE_MATRIX_API_URL` (set by `hive-c0re.nix` from /// `HIVE_MATRIX_API_URL` (set by `hive-c0re.nix` from
/// `hyperhive.matrix.apiUrl`). /// `services.hyperhive.swarm.matrix.apiUrl`).
/// ///
/// `None` means **this hive has no homeserver to provision against** and /// `None` means **this hive has no homeserver to provision against** and
/// every matrix path no-ops — see [`is_present`]. There is deliberately no /// every matrix path no-ops — see [`is_present`]. There is deliberately no
@ -43,7 +44,8 @@ fn matrix_http() -> Option<&'static str> {
/// rather than the missing variable. /// rather than the missing variable.
fn matrix_base() -> Result<&'static str> { fn matrix_base() -> Result<&'static str> {
matrix_http().context( matrix_http().context(
"matrix: no homeserver configured (hyperhive.matrix.apiUrl / HIVE_MATRIX_API_URL) — \ "matrix: no homeserver configured \
(services.hyperhive.swarm.matrix.apiUrl / HIVE_MATRIX_API_URL) \
this path should have been gated on matrix::is_present()", this path should have been gated on matrix::is_present()",
) )
} }

View file

@ -472,8 +472,8 @@ fn require_matrix_present() -> Result<()> {
return Ok(()); return Ok(());
} }
anyhow::bail!( anyhow::bail!(
"no matrix homeserver configured — set services.hyperhive.matrix.enable = true to run one \ "no matrix homeserver configured — set services.hyperhive.swarm.matrix.enable = true to run one \
here, or services.hyperhive.matrix.apiUrl to point at an existing one, before \ here, or services.hyperhive.swarm.matrix.apiUrl to point at an existing one, before \
provisioning matrix users" provisioning matrix users"
) )
} }

View file

@ -30,7 +30,7 @@ pub(crate) async fn open_url(socket: &Path, target: OpenTarget) -> Result<()> {
), ),
OpenTarget::Matrix => ( OpenTarget::Matrix => (
urls.matrix, urls.matrix,
"the matrix GUI URL needs `services.hyperhive.matrix.gui.enable = true`", "the matrix GUI URL needs `services.hyperhive.swarm.matrix.gui.enable = true`",
), ),
}; };
let url = url.with_context(|| format!("no URL available for this surface — {hint}"))?; let url = url.with_context(|| format!("no URL available for this surface — {hint}"))?;