docs(networking): fix round — argus review + audit E1/E2
observability.md: "Why two tiers" claimed the harness currently writes an upstream token into the agent's own claude settings; that path was removed with the direct-export mode it served (nix/agent-modules/otel.nix:56-63). Reworded as the hypothetical the paragraph is actually making. gateway.md: restored the agent-trust pointer to /run/hive-ca/trust-bundle.pem in "Cert prompts" (hive-ca-trust.nix:41), dropped by the earlier rewrite. Corrected the SPA-fallback section: only the chat.<swarm> vhost uses the Accept-header map (hive-matrix.nix:693-696); per-agent split mode uses file-existence try_files (gateway_nginx.rs:93-134), not the same mechanism. Refs #3902
This commit is contained in:
parent
067f4e5699
commit
54556e4661
2 changed files with 8 additions and 9 deletions
|
|
@ -59,10 +59,11 @@ the control plane, so degraded telemetry isn't degraded operation.
|
|||
### Why two tiers
|
||||
|
||||
**The hive tier isn't optional.** Exporting straight to `endpoint` would mean
|
||||
every agent needs the credential — and the harness delivers that token into
|
||||
the agent's own `~/.claude/settings.json`, a file the agent can read. `0600`
|
||||
protects it from other containers, not from the agent itself. An option that
|
||||
could select the direct path would reopen that hole.
|
||||
every agent needs the credential — and the only place to hand it to an agent
|
||||
container is somewhere the agent itself can read, its own claude settings
|
||||
among them. `0600` protects a secret from other containers, not from the
|
||||
agent it belongs to. An option that could select that path would reopen the
|
||||
hole.
|
||||
|
||||
**The tiers stay separate on one box.** An all-local hive is a statement about
|
||||
_where_ processes run, not about the shape of the deployment. A boundary that
|
||||
|
|
|
|||
Loading…
Reference in a new issue