docs(swarm): dedupe CA summary, drop stale/inaccurate fn refs

This commit is contained in:
iris 2026-08-15 11:44:26 +02:00 committed by mara
commit c681b8a340

View file

@ -73,14 +73,11 @@ and `qualify()` / `qualified_label()` semantics.
## Swarm CA ## Swarm CA
A hive's internal TLS chains to a **swarm root CA**: the root signs each A hive's internal TLS chains to a **swarm root CA**, so a peer that
hive's own CA, and that hive CA signs the gateway leaf, so a peer that trusts the root validates every hive in the swarm rather than being
trusts the root once validates every hive in the swarm rather than being pinned to each one by hand. Provisioning modes, what to hand a peer
pinned to each one by hand. (`trust-bundle.pem`, never `ca.pem`), the name constraints on a hive
CA, and how an existing hive adopts the hierarchy: [`ca.md`](ca.md).
Provisioning modes, what to hand a peer (`trust-bundle.pem`, never
`ca.pem`), the name constraints on a hive CA, and how an existing hive
adopts the hierarchy: [`ca.md`](ca.md).
## Running the swarm's shared services ## Running the swarm's shared services
@ -183,17 +180,17 @@ environment and forwarded to agent containers.
## What the config does at runtime ## What the config does at runtime
1. **Dashboard P33RS tab**`parse_peer_hives()` in `dashboard.rs` 1. **Dashboard P33RS tab** — hive-c0re reads `HYPERHIVE_PEERS` and
reads `HYPERHIVE_PEERS` and includes surfaces it as the peer list in the dashboard's state API. The
`peer_hives: Vec<{ name, url }>` in `/api/state`. The dashboard dashboard shows a P33RS tab (hidden when the list is empty) with a
shows a P33RS tab (hidden when the list is empty) with a card per card per peer linking to `https://{domain}/`. Wire format + module
peer linking to `https://{domain}/`. See pointer: `docs/web-ui/dashboard.md` § P33RS tab.
`docs/web-ui/dashboard.md` § P33RS tab.
2. **Agent identity** — the same `HYPERHIVE_PEERS` env var is 2. **Agent identity** — the same `HYPERHIVE_PEERS` env var is
forwarded to agent containers by `meta.rs`; agent code can call forwarded to agent containers, so agent code can discover peer
`identity::peers()` to discover peer hives and address them with hives and address them with qualified names (`agent@domain`). See
qualified names (`agent@domain`). `hive-agent/src/identity.rs`'s module doc for the label/domain
helpers.
3. **Matrix federation** — when `matrix.enable` is on, tuwunel 3. **Matrix federation** — when `matrix.enable` is on, tuwunel
federates with the peer's matrix server (discovered via the peer's federates with the peer's matrix server (discovered via the peer's