Watch
0
0
Fork
You've already forked hyperhive
0

swarm-otel: ship the whole host journal, drop user sessions after it

The swarm collector's journald receiver read only the units listed in
`services.hyperhive.swarm.otel.journaldUnits`. A unit nobody listed
never reached the store, and a misspelt entry shipped nothing without
an error. The list existed to keep an operator's desktop session out of
a store every swarm operator can read, but the receiver can only match
positively, so the only way to express "not user sessions" was to name
every service instead.

The receiver now reads the whole host journal, and a new
`filter/exclude-user-sessions` processor in the `logs/<swarm>` pipeline
drops records whose `_SYSTEMD_SLICE` is `user-<uid>.slice` (session
scopes and `user@<uid>.service`). The per-hive `logs/<hive>` pipelines
carry agent-container journals only and get no filter.

`journaldUnits` is removed with `mkRemovedOptionModule`, together with
its non-empty assertion and the entry each host module added. The four
module-eval membership checks go with it, replaced by one structural
case in swarm-otel-core.

Closes #3646
This commit is contained in:
atlas 2026-09-30 22:51:52 +02:00 • committed by mara
commit 6b1e825c0a
25 changed files with 72 additions and 324 deletions

View file

@ -159,26 +159,6 @@ in
services.hyperhive.gateway.dns.enable = lib.mkDefault true;
services.hyperhive.network.enable = lib.mkDefault true;
# The daemon that owns every container on this hive, and the helper it
# delegates its root operations to. An agent asking why a container did
# not come up is asking about one of these two.
#
# The four agent-side units are named here rather than by the
# `agent-modules/` that define them, which is the one case where "a
# module names its own units" cannot hold: those modules are evaluated
# inside the guest, and this option belongs to the host. This module is
# the host's only knowledge that agent containers exist at all. They are
# also exactly the units the dashboard offers as journal filters, so
# without them the store cannot answer a question the UI can ask.
services.hyperhive.swarm.otel.journaldUnits = [
"hive-c0re"
"hive-priv"
"hive-agent"
"hive-mcp-http"
"hive-bash-daemon"
"hive-matrix-daemon"
];
assertions = [
{
# The pinned claude reaches agents as a bare path, so this