Watch
0
0
Fork
You've already forked hyperhive
0

docs: drop statements about absent things, state current behaviour

This commit is contained in:
atlas 2026-10-02 09:26:41 +02:00
commit b83fdc60f3
4 changed files with 22 additions and 30 deletions

View file

@ -13,12 +13,12 @@ catalogued below.
Telemetry crosses two collectors, and which one you configure depends on what
the host is:
| | runs where | receives from | does |
| ------------------------------------ | ---------------------- | --------------------------------- | --------------------------------------------------------------------- |
| **swarm tier** — `deploy.swarm-otel` | once per swarm | every hive's collector | writes the swarm's stores and exports upstream |
| **hive tier** — `otel.enable` | every hive with agents | that hive's agents, on the bridge | forwards to the swarm tier. Holds no credential, picks no destination |
| | runs where | receives from | does |
| ------------------------------------ | ---------------------- | --------------------------------- | ----------------------------------------------- |
| **swarm tier** — `deploy.swarm-otel` | once per swarm | every hive's collector | writes the swarm's stores and exports upstream |
| **hive tier** — `otel.enable` | every hive with agents | that hive's agents, on the bridge | forwards to the swarm tier. Holds no credential |
An all-local host runs both, and needs nothing said about the hop between them.
An all-local host runs both; the hop between them configures itself.
```nix
services.hyperhive.otel = {
@ -31,7 +31,7 @@ services.hyperhive.otel = {
## Enabling export
`otel.enable` is the single gate on a hive: one switch in the host config
covers every agent container on it, with no per-agent opt-in or opt-out.
covers every agent container on it.
`endpoint` is where telemetry ends up after it leaves the swarm — optional,
because the swarm's own metrics store (`deploy.victoriametrics`) is a
destination in its own right. With both, telemetry goes to both. See
@ -50,7 +50,7 @@ The hive collector reaches the swarm collector by its gateway name
(`swarm.otel.domain`, default `otel.<swarm domain>`) — the same DNS-and-CA-trust
shape every hive-to-swarm-service hop uses. On the host running the swarm
collector the hive's dnsmasq answers that name; elsewhere it resolves through
ordinary DNS. Nothing here needs setting for the split-host case.
ordinary DNS.
⚠️ **The hive collector carries every bit of that hive's telemetry.** It
runs on the same host as the agents and restarts on failure. Telemetry isn't
@ -62,8 +62,7 @@ the control plane, so degraded telemetry isn't degraded operation.
every agent needs the credential — and the only place to hand it to an agent
container is somewhere the agent itself can read, its own claude settings
among them. `0600` protects a secret from other containers, not from the
agent it belongs to. An option that could select that path would reopen the
hole.
agent it belongs to.
**The tiers stay separate on one box.** An all-local hive is a statement about
_where_ processes run, not about the shape of the deployment. A boundary that