diff --git a/nix/templates/harness-base.nix b/nix/templates/harness-base.nix index 1dc89c8d..3c2ba44e 100644 --- a/nix/templates/harness-base.nix +++ b/nix/templates/harness-base.nix @@ -132,41 +132,9 @@ in Constraints match `useradd`'s NAME_REGEX: lowercase / `_` start, total length ≤ 31, no special characters. UID is auto-assigned - by NixOS unless `hyperhive.user.uid` is explicitly set. - ''; - }; - - options.hyperhive.user.uid = lib.mkOption { - type = lib.types.nullOr lib.types.int; - default = null; - example = 1100; - description = '' - Optional fixed UID for the per-agent unix user. `null` (default) - lets NixOS auto-assign from the normal-user range (≥ 1000), - which is the right default for most deployments — the UID stays - stable across container rebuilds because each container only has - one normal user and the assignment is written into the container's - `/etc/passwd` at activation time. - - Set an explicit value only when the host needs a predictable UID - for the agent's state files — e.g. if an operator script - references files by numeric UID, or to keep ownership stable - across full container destroy + recreate on a fresh host. - - Values must be in `[1000, 60000)`. Using UIDs < 1000 clashes with - system accounts and is rejected by NixOS. - ''; - }; - - options.hyperhive.user.gid = lib.mkOption { - type = lib.types.nullOr lib.types.int; - default = null; - example = 1100; - description = '' - Optional fixed GID for the per-agent unix group. `null` (default) - lets NixOS auto-assign. Usually set alongside `hyperhive.user.uid` - to the same value (the conventional Unix pattern for per-user - groups where uid == gid), but can be set independently. + by NixOS; no `uid =` override surface (intentional — pinning + across rebuilds isn't a concern when the home and state dirs + stay bind-mounted from the host). ''; }; @@ -1095,35 +1063,14 @@ in `..` path segments. ''; } - { - assertion = - config.hyperhive.user.uid == null - || (config.hyperhive.user.uid >= 1000 && config.hyperhive.user.uid < 60000); - message = '' - hyperhive.user.uid must be in [1000, 60000) — values below - 1000 clash with system accounts; values ≥ 60000 are reserved - by NixOS for dynamic allocation. Leave unset (null) to let - NixOS auto-assign. - ''; - } - { - assertion = - config.hyperhive.user.gid == null - || (config.hyperhive.user.gid >= 1000 && config.hyperhive.user.gid < 60000); - message = '' - hyperhive.user.gid must be in [1000, 60000) — same range - constraint as hyperhive.user.uid. - ''; - } ]; # Per-agent unix user. Runs the hive harness + # co-process daemons under a non-root principal. UID auto-assigned by - # NixOS unless `hyperhive.user.uid` is set. The container activation - # script (hive-agent-user-migrate) chowns the bind-mounted state dir - # — including credential files written by hive-c0re before the - # container was built — to this user on every boot, so agent - # processes can always read their own tokens. + # NixOS. The container activation script (hive-agent-user-migrate) + # chowns the bind-mounted state dir — including credential files + # written by hive-c0re before the container was built — to this user + # on every boot, so agent processes can always read their own tokens. users.users.${userName} = { isNormalUser = true; home = homeDir; @@ -1135,15 +1082,8 @@ in # the system default for the root user too (see SHELL env # var declaration below). shell = pkgs.bashInteractive; - } - // lib.optionalAttrs (config.hyperhive.user.uid != null) { - uid = config.hyperhive.user.uid; }; - users.groups.${userName} = - { } - // lib.optionalAttrs (config.hyperhive.user.gid != null) { - gid = config.hyperhive.user.gid; - }; + users.groups.${userName} = { }; # `NOPASSWD: ALL` for the agent user. Lets claude's Bash tool # keep working with anything that expected root (systemctl,