Watch
0
0
Fork
You've already forked hyperhive
0

swarm: show subagent terminals in the swarm UI

An agent's subagent daemon publishes each subagent's output as terminal
rows on `$SWARM.term.<agent>.sub.<subagent>`, as the agent, into a
per-agent stream it creates itself; swarm-controller lists an agent's
subagents from that stream's subjects and relays one subagent's rows as
SSE; the swarm UI lists them under the agent's terminal preview and
reuses AgentTermPreview, full-screen tab included, with no input.

- swarm-nats.nix: the agent token may also publish
  `$SWARM.term.{agent}.sub.>` and `$JS.API.STREAM.CREATE|INFO` on
  `term-sub-{agent}`, and nothing else of JetStream. A module-eval arm
  pins the agent-token grant as an exact list.
- mcp.nix: hive-subagent-daemon loads the agent's store identity
  (`hive-agent-bao-cert/-key/-server-ca`, the ones hive-agent loads)
  whenever the agent has a store, not only on the opencode preset. The
  agent's own queue secret lives in the store, so this is the credential
  the harness connects with.
- hive-subagent-mcp: `swarm_term` reads the agent's queue secret under
  that identity, connects with the agent token, opens or creates
  `term-sub-<agent>` (max_age 24h), and publishes classified rows from
  the sink every subagent line already passes through. The sink only
  queues (bounded, drop-and-count); a missing store, refused credential,
  failed stream create or failed publish is a log line.
- The stream-json classifier (`stream_enrich`) and the `TermMsg` row
  types plus `fit` move from the hive-agent binary into hive-sh4re, so
  the subagent daemon publishes the rows AgentTermPreview already
  renders. hive-agent keeps its LiveEvent classifier on top.
- swarm-controller: `GET /api/agents/{name}/subagents` and
  `GET /api/agents/{name}/subagents/{subagent}/term/stream`.
- docs/swarm: what the UI shows and what the queue carries.

Closes #4827
This commit is contained in:
atlas 2026-10-02 22:09:43 +02:00 • committed by mara
commit d6f94e5247
35 changed files with 1529 additions and 340 deletions

View file

@ -31,11 +31,14 @@ let
# (several agents that rarely compile at the same time) working.
subagentMemoryHigh = containerMemoryMaxBytes * 2 / 3;
# Set on the harness only for an ACP agent on the opencode preset
# (./agent-service.nix). The subagent daemon then reads that key from the
# store as this agent, so it is handed the same store identity
# ./queue-identity.nix hands the harness.
# (./agent-service.nix).
acpApiKeyEnv = config.systemd.services.hive-agent.environment.HIVE_ACP_API_KEY_ENV or null;
subagentReadsStore = acpApiKeyEnv != null && config.services.hyperhive.agent.bao.addr != null;
# The subagent daemon reads this agent's own queue credential from the
# store, to publish its subagents' terminals as the agent, and on the
# opencode preset the provider key too. Either way it is handed the same
# store identity ./queue-identity.nix hands the harness, under the same
# switch.
subagentReadsStore = config.services.hyperhive.agent.bao.addr != null;
in
{
options.services.hyperhive.agent.allowedRecipients = lib.mkOption {

View file

@ -844,6 +844,16 @@ in
# on a hive presents that one, so it cannot be scoped to one
# agent's key.
"--agent-token-publish-subject ${lib.escapeShellArg "\$\$KV.agent-icons.{agent}"}"
# Its subagents' terminal rows, and the one stream that keeps
# them (`swarm_queue_client::subagent_term`). The agent's
# subagent daemon creates the stream on first use, so it gets
# `CREATE` and `INFO` on that stream name alone: no `UPDATE`,
# no `DELETE`, no consumer, no other stream. A `CREATE`'s
# config travels in its payload, which no subject grant can
# narrow.
"--agent-token-publish-subject ${lib.escapeShellArg "\$\$SWARM.term.{agent}.sub.>"}"
"--agent-token-publish-subject ${lib.escapeShellArg "\$\$JS.API.STREAM.CREATE.term-sub-{agent}"}"
"--agent-token-publish-subject ${lib.escapeShellArg "\$\$JS.API.STREAM.INFO.term-sub-{agent}"}"
"--store-cert-role ${lib.escapeShellArg authCertRole}"
];
# Every credential arrives by `LoadCredential` and is named

View file

@ -86,13 +86,32 @@ let
&& (subagent opencode).environment.HIVE_ACP_API_KEY_ENV == "T_PROVIDER_KEY";
}
{
# Only the opencode preset has a provider key variable; any other ACP
# command reads nothing from the store.
# Only the opencode preset has a provider key variable.
name = "an ACP agent off the opencode preset is told no provider key variable";
ok =
!((harness acpBao).environment ? HIVE_ACP_API_KEY_ENV)
&& (subagent acpBao).environment.HIVE_ACP_API_KEY_ENV or null == null
&& !((subagent acpBao).serviceConfig ? LoadCredential);
&& (subagent acpBao).environment.HIVE_ACP_API_KEY_ENV or null == null;
}
{
# Every agent with a store, whatever its runtime: the daemon reads the
# agent's queue credential with it to publish subagent terminals.
name = "a subagent daemon gets the agent's store identity whenever the agent has a store";
ok =
lib.all
(
u:
u.serviceConfig.LoadCredential == [
"hive-agent-bao-cert"
"hive-agent-bao-key"
"hive-agent-bao-server-ca"
]
&& u.environment.HIVE_AGENT_NAME == "a1"
&& u.environment.BAO_ADDR == "https://bao.t.local:8200"
)
[
(subagent acpBao)
(subagent opencodeBao)
];
}
{
name = "an opencode agent's subagent daemon gets the agent's store identity";

View file

@ -161,6 +161,32 @@ let
in
lib.hasInfix "--agent-token-publish-subject '$$KV.agent-icons.{agent}'" exec;
}
{
# The whole per-agent grant, compared as a list rather than by infix: a
# wider subject added beside these (`$$JS.API.>`, another stream's name)
# would pass every presence check above.
name = "a verified agent's grant is exactly its own subjects and its subagent stream";
ok =
let
args = lib.splitString " " (responderOf natsOldPath).serviceConfig.ExecStart;
granted = lib.concatLists (
lib.imap0 (
i: a:
lib.optional (a == "--agent-token-publish-subject" && i + 1 < lib.length args) (
lib.elemAt args (i + 1)
)
) args
);
in
granted == [
"'$$SWARM.term.{agent}'"
"'$$SWARM.agent-state.{agent}'"
"'$$KV.agent-icons.{agent}'"
"'$$SWARM.term.{agent}.sub.>'"
"'$$JS.API.STREAM.CREATE.term-sub-{agent}'"
"'$$JS.API.STREAM.INFO.term-sub-{agent}'"
];
}
{
# Each credential by `LoadCredential`, and the environment naming where
# the unit sees it: a DynamicUser cannot read the copies directly.