Watch
0
0
Fork
You've already forked hyperhive
0

docs(swarm): state behaviour instead of denying absent options

This commit is contained in:
atlas 2026-10-02 09:30:43 +02:00 • committed by mara
commit 7b226f21dd
3 changed files with 9 additions and 15 deletions

View file

@ -46,10 +46,9 @@ identity, forge user, config repo, store identity and matrix account, then
sends the hive a deploy message. A new agent starts `paused`. sends the hive a deploy message. A new agent starts `paused`.
`services.hyperhive.deploy.swarm-controller.enable` runs it on this host; `services.hyperhive.deploy.swarm-controller.enable` runs it on this host;
`singleHostSwarm` turns it on. **Otherwise off by default and deliberately `singleHostSwarm` turns it on. **Otherwise off: set it on the one host that
not derived from `deploy.hive-controller.enable`**: a swarm has one runs the controller.** A swarm has one controller, so enabling it states a
controller, so enabling it states a fact about swarm topology, not about fact about swarm topology, not about whether this host runs a hive.
whether this host runs a hive.
What it serves, why it's a unix socket rather than a port, and the What it serves, why it's a unix socket rather than a port, and the
socket-directory constraint that governs where `socketPath` may point: socket-directory constraint that governs where `socketPath` may point:
@ -254,10 +253,9 @@ re-derive. Approval happens once, at the swarm level: a hive receives a
decision, not an event to adjudicate. decision, not an event to adjudicate.
**`internal/knowledge` is on that path.** The controller's is the only **`internal/knowledge` is on that path.** The controller's is the only
hook on it; hives register none of their own hook on it ([`knowledge.md`](../integrations/knowledge.md) covers clearing a
([`knowledge.md`](../integrations/knowledge.md) covers clearing a leftover). leftover). A webhook has exactly one target URL, so a second registration
A webhook has exactly one target URL, so a second registration would take would take delivery away from the first rather than add a recipient.
delivery away from the first rather than add a recipient.
<!-- vale write-good.Passive = NO --> <!-- vale write-good.Passive = NO -->

View file

@ -26,8 +26,7 @@ host's `/etc/hosts` entries for the names it serves
(`gateway.localHostsEntry`), the queue's auth-callout keys (`gateway.localHostsEntry`), the queue's auth-callout keys
(`deploy.nats.autoGenerateCallout`) and where the secret store's bootstrap (`deploy.nats.autoGenerateCallout`) and where the secret store's bootstrap
token goes (`deploy.bao.bootstrapTokenFile`). You can still set each derived token goes (`deploy.bao.bootstrapTokenFile`). You can still set each derived
toggle on its own, which wins, so "all local except X" needs no further toggle on its own, and that setting wins.
option.
**Both default to off**, and that's deliberate: a host can't tell **Both default to off**, and that's deliberate: a host can't tell
whether it's meant to be the swarm's service host, so this is an whether it's meant to be the swarm's service host, so this is an
@ -210,9 +209,7 @@ gateway either way.
**Both store exporters are unconditional**, and `deploy.victoriametrics.enable` **Both store exporters are unconditional**, and `deploy.victoriametrics.enable`
doesn't gate them: that option says this host _runs_ the store, while the swarm doesn't gate them: that option says this host _runs_ the store, while the swarm
has one either way, reached by its swarm name through the gateway. A collector has one either way, reached by its swarm name through the gateway.
with no exporter would receive from every hive and drop it silently, because an
absent exporter isn't an error.
Agent-side configuration, and what a hive's own collector does, are in Agent-side configuration, and what a hive's own collector does, are in
[`../scheduler/observability.md`](../scheduler/observability.md). [`../scheduler/observability.md`](../scheduler/observability.md).

View file

@ -32,8 +32,7 @@ that.
## One file, two writers ## One file, two writers
`swarmctl` reads and writes `users.yml` — authelia's own users database — `swarmctl` reads and writes `users.yml` — authelia's own users database —
directly, with no second store. `swarm-authelia-bridge` writes agent directly. `swarm-authelia-bridge` writes agent subjects into the same file.
subjects into the same file.
⚠️ The file is round-tripped, so **comments and hand-formatting do not ⚠️ The file is round-tripped, so **comments and hand-formatting do not
survive a write**. Values do, and so do keys this binary does not model. survive a write**. Values do, and so do keys this binary does not model.