Commit graph

  • 5cd7f866f4 swarm-bao: grant the agent PKI mount (for #4756) main atlas 2026-09-27 17:54:35 +02:00
  • e9cec0da21 swarm-bao: write every swarm-* grant as a bao granter, not with a 24h token atlas 2026-09-27 03:33:38 +02:00
  • 19cc1b12e2 hive-screen-mcp: bound grim/wtype and VNC calls; hive-c0re: make messages match the code atlas 2026-09-26 23:28:09 +02:00
  • 3385aaf026 docs: drop "simply" from the knowledge sweep page atlas 2026-09-27 19:22:00 +02:00
  • 313d582c01 job_queue: drop insert_unless_live, accept extra queue passes atlas 2026-09-27 19:09:49 +02:00
  • 1d4c77d2c8 hive-c0re: serialise the matrix and knowledge sweeps through the job queue atlas 2026-09-27 02:55:59 +02:00
  • 2252c55df8 hive-priv: create agent socket dirs on start; drop hyperhive-agents.conf atlas 2026-09-27 04:51:07 +02:00
  • e7456a49ff nix flake update flake-bot 2026-09-27 14:25:17 +02:00
  • 7ac6819652 hive-c0re: fail on a malformed agent name and on an unreadable container list atlas 2026-09-26 15:18:41 +02:00
  • ee25b7de20 hive-forge-notify: a failed assigned-count poll leaves the rollup todo unchanged atlas 2026-09-27 00:02:18 +02:00
  • fc85d0ee7e hive-priv: publish config files by rename, bound the toplevel build atlas 2026-09-26 19:39:50 +02:00
  • bfd8189900 hive-c0re: stop reporting refused invites as success; re-register the config-PR hook when its secret changes atlas 2026-09-26 19:01:15 +02:00
  • 0f58cdbde2 swarm-queue-client: install aws-lc-rs as the process rustls provider atlas 2026-09-26 19:57:01 +02:00
  • 386741d38f hive-c0re: keep agent and manager listeners alive across accept errors atlas 2026-09-26 00:17:59 +02:00
  • 65a1f8d902 hive-c0re: bound request lines on the agent and manager sockets atlas 2026-09-26 00:15:22 +02:00
  • 7b1fe5f9d3 hive-sock-client, web proxy, HTTP clients: bound connect and response waits atlas 2026-09-26 18:29:48 +02:00
  • 6fac00dcc5 hive-c0re: fail on an unparseable resource-limits or topology file, write both atomically atlas 2026-09-26 15:16:31 +02:00
  • 97cf8a1b2b agent-modules: write bao's stderr where UMask=0377 lets it, name what failed atlas 2026-09-26 19:24:32 +02:00
  • c6a778f666 lint: tighten atomic-write-secret.nix's header comment; fix vale contractions in persistence.md atlas 2026-09-26 19:19:35 +02:00
  • 770f68c272 host-modules: atomic_write_secret takes the value as an argument, not stdin atlas 2026-09-26 18:30:16 +02:00
  • 7a9fadc21a host-modules: convert swarm-bao's HSM-PIN env writer to atomic_write_secret atlas 2026-09-26 18:05:40 +02:00
  • 5466cec066 host-modules: fix atomic_write_secret's leftover-tmp bug; convert swarm-bao's forwarder-oidc writer too atlas 2026-09-26 15:42:30 +02:00
  • ed53e9abcc host-modules: write credential files atomically; agent-modules: retry a failed .claude migration atlas 2026-09-26 15:16:42 +02:00
  • c978060824 hive-c0re: an unreadable capabilities file denies ManageRootAgent mounts atlas 2026-09-26 14:43:53 +02:00
  • e0b08fe362 hive-c0re: fail on an unparseable permission file, write it atomically atlas 2026-09-26 02:17:54 +02:00
  • 4f3209d8c7 nix flake update flake-bot 2026-09-26 11:11:20 +02:00
  • 1948e7ad23 module-eval: read the services-leaf narrowing off a forge host atlas 2026-09-26 00:57:42 +02:00
  • 3202cde704 nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable atlas 2026-09-26 00:32:32 +02:00
  • ed2ec52fe5 swarm-tls: narrow each gateway's services leaf to the names it fronts atlas 2026-09-23 22:31:57 +02:00
  • 0649673ebf hive-tls: renew the swarm-services leaf on a daily timer atlas 2026-09-25 20:32:28 +02:00
  • afde9f380f module-eval: give the forgejo-mirror fixtures deploy.forgejo.enable atlas 2026-09-25 02:01:48 +02:00
  • 20419ccd41 swarm-controller: own the swarm-wide forge objects; hive-c0re stops creating them atlas 2026-09-24 15:00:10 +02:00
  • 85ba45b2de docs: agents' matrix accounts come from the swarm atlas 2026-09-25 02:12:26 +02:00
  • 89a5dd752c hive-c0re: stop minting agents' matrix accounts atlas 2026-09-25 02:08:23 +02:00
  • ab153bda2f hive-matrix-mcp: read the main account's token from the store too atlas 2026-09-25 01:57:25 +02:00
  • 2776e121e5 swarm-controller: mint each agent's matrix account with the swarm's token atlas 2026-09-25 00:25:06 +02:00
  • 9308752a09 hive-matrix: load the swarm's appservice and promote its sender atlas 2026-09-24 23:57:05 +02:00
  • 89aff8d613 swarm-matrix-ctl: mint the swarm's own appservice registration atlas 2026-09-24 23:42:36 +02:00
  • cb176c7be7 swarm-bao: stamp collector's service.name as "bao" atlas 2026-09-24 21:37:58 +02:00
  • 0cbb7db2c0 docs: a first SSO login makes a human's forge account atlas 2026-09-25 02:11:44 +02:00
  • d56d8f2b36 swarmctl: forge make-admin atlas 2026-09-25 02:01:57 +02:00
  • f1f59ea165 swarm-controller: make an existing forge user a site admin atlas 2026-09-25 00:04:44 +02:00
  • ef494af188 hivectl: drop forge create-user; SSO makes a human's forge account atlas 2026-09-24 23:59:13 +02:00
  • 113f3fe6e2 hive-forge: a first authelia login creates the forge account atlas 2026-09-24 23:53:15 +02:00
  • 2cc3d62d5f nix flake update flake-bot 2026-09-25 05:00:36 +02:00
  • c4edb78aa2 swarm-otel: correct the hostJournalDir comment for swarm-bao's exception atlas 2026-09-24 23:44:32 +02:00
  • 44009dc51d swarm-bao: stop linking the container's journal onto the host atlas 2026-09-24 23:12:10 +02:00
  • 92e1909caf swarm-bao: give the store forwarder's OIDC reader its own bao identity atlas 2026-09-24 17:25:34 +02:00
  • 46d0b46670 hive-c0re: decide matrix token presence from metadata, not by reading it atlas 2026-09-24 11:01:03 +02:00
  • 978164dc53 nix: run the forge on one host per swarm (deploy.forgejo.enable) atlas 2026-09-24 19:44:04 +02:00
  • 21c17772b8 swarm-controller: fix test helper's forge::Client initializer atlas 2026-09-24 20:29:42 +02:00
  • f62ec349d5 workers: skip a cycle instead of spawning/alerting on an unreadable container list atlas 2026-09-24 12:50:07 +02:00
  • 3ee5a960b4 docs/setup: ruth needs a store identity and a rebuild, not a hand-made forge user atlas 2026-09-24 17:39:14 +02:00
  • 22f0acfd6d swarm-controller: the forge-token backfill creates a missing forge user atlas 2026-09-24 17:37:09 +02:00
  • abc942cff3 docs: the swarm mints agent forge tokens; hive-c0re and tea-login no longer do atlas 2026-09-24 16:43:54 +02:00
  • 6d0c30ade2 module-eval: pin the agent forge-token fetch and tea-login's removal atlas 2026-09-24 16:40:38 +02:00
  • b5d07d4df2 hive-c0re: stop minting agent forge tokens atlas 2026-09-24 16:39:45 +02:00
  • dd32a395f7 agents: pull the forge token from bao; drop tea-login atlas 2026-09-24 16:35:40 +02:00
  • 52c8c0b0de swarm-controller: mint each agent's forge token and store it in bao atlas 2026-09-24 16:29:04 +02:00
  • 2fda529ca8 swarm-controller: accept the legacy pre-alignment email in the lockdown guard atlas 2026-09-24 15:40:18 +02:00
  • 58f50ed506 swarm-controller: guard the lockdown PATCH against a forge name collision atlas 2026-09-24 15:11:23 +02:00
  • 04d5bf5f3e swarm-controller: disable repo creation on the agent forge users it creates atlas 2026-09-24 13:34:04 +02:00
  • 065b11a99d swarm-controller: page repo_search past forgejo's first page atlas 2026-09-24 11:59:50 +02:00
  • a5259146dc swarm: default every queue URL to the queue's name on every hive atlas 2026-09-24 16:40:26 +02:00
  • 0081d75c86 swarm-bao: grant the bootstrap token the queue's pki role, policy and login role atlas 2026-09-24 16:31:49 +02:00
  • 1d261b3fed swarm-nats: give the queue a name, a bao-issued leaf, and require TLS atlas 2026-09-24 15:43:25 +02:00
  • 244db367c4 swarm-controller: answer 404, not 503, for an issue-report on a nonexistent repo atlas 2026-09-24 16:26:40 +02:00
  • d048fee698 docs/setup: point at the bootstrap policy file instead of inlining a copy (#4698) atlas 2026-09-24 15:54:38 +02:00
  • e3c595857e swarm-bao: keep the bootstrap policy in one file, checked against the units using it (#4698) atlas 2026-09-24 15:53:53 +02:00
  • 88e571a463 swarm-controller: refuse a new agent name the forge would reject atlas 2026-09-24 14:30:31 +02:00
  • 6a87b25488 swarm-controller: answer 503 on a disconnected queue, not 500 or a hang atlas 2026-09-24 14:05:18 +02:00
  • 0bfe354b6d nix: move the reader-after-policy edges into their own colocation glue atlas 2026-09-24 14:04:49 +02:00
  • cde3fec956 module-eval: pin each swarm-bao reader's ordering after its policy unit atlas 2026-09-24 13:08:40 +02:00
  • c92bb0dce7 nix: order each swarm-bao secret reader after the policy unit writing its role atlas 2026-09-24 13:07:18 +02:00
  • aa719da571 nix: ship the journals of the units an apply can leave failed atlas 2026-09-24 13:07:44 +02:00
  • fdb847cd87 hive-priv: stop run_forge_admin's bail! from reproducing --password atlas 2026-09-24 11:35:53 +02:00
  • 9986da4c7f hive-forge: attach-issue/attach-comment fail on a missing download URL atlas 2026-09-24 12:58:05 +02:00
  • 6ac402ed2d hive-forge: labels remove refuses unknown names and verifies removal landed atlas 2026-09-24 12:58:01 +02:00
  • 6d10c1367e hive-priv: don't leave a partial snapshot export at dest on failure atlas 2026-09-24 13:23:14 +02:00
  • 295925abb6 swarm-controller: don't fold every 422 into "already exists" on user/repo create atlas 2026-09-24 12:24:50 +02:00
  • e3fefb8c5f docs: fix markdown indent treefmt wants after removing the ownership-checks bullet atlas 2026-09-23 18:42:13 +02:00
  • a65dbee982 docs: delete two more stale manager-override claims atlas 2026-09-23 17:50:33 +02:00
  • d2c4c8d4a3 docs: drop dead-claim narration for the retired loose-ends override atlas 2026-09-23 17:11:45 +02:00
  • f53508cb2b docs, hive-c0re: retire prose describing the removed get_loose_ends target atlas 2026-09-23 16:27:40 +02:00
  • 7dd52207de dashboard: fail purge-tombstone closed when the container list is unreadable atlas 2026-09-24 11:38:29 +02:00
  • 11cd2038c9 hive-priv: refuse symlinks when writing the bridge-DNS marker atlas 2026-09-24 11:13:34 +02:00
  • 18bd8dd2c7 hive-c0re: fail a nixos-container destroy that leaves the container in place atlas 2026-09-24 11:00:51 +02:00
  • 5b54b6ddc8 swarm-bao: fail the unit when the services root cannot be read, instead of replacing it atlas 2026-09-24 11:00:20 +02:00
  • c0c031a5e4 swarm-bao: let the journald receiver read the host-linked journal atlas 2026-09-23 23:19:31 +02:00
  • 33da51382e subagent: make interrupt cancel a goal run, not just its turn atlas 2026-09-21 22:31:44 +02:00
  • 11ec050ca8 hive-tls: give swarm-services-cert the cmp it tests the root with müde 2026-09-23 22:18:32 +02:00
  • 5704c0c583 nix: unbreak the swarm-services leaf the gateway waits on müde 2026-09-23 21:36:46 +02:00
  • 22a87f7268 docs/swarm/{ca,secrets}.md: reword the 8 vale write-good.Passive / Microsoft.Contractions hits atlas 2026-09-21 23:34:07 +02:00
  • f4df4fc4a9 nix: issue the swarm-services leaf from bao's pki mount atlas 2026-09-21 17:59:22 +02:00
  • ebcc5bde89 swarm-bao: shrink the read-grant comment under the comment-block max atlas 2026-09-23 18:46:32 +02:00
  • 87174863ca swarm-bao: grant the controller read on the agent credential prefix atlas 2026-09-23 17:59:34 +02:00
  • e2ff4f5281 swarm-bao: give the store's collector an explicit self-telemetry port atlas 2026-09-23 18:04:33 +02:00
  • 5cec69bd21 otel.nix: trim the StartLimit comment block to the load-bearing points atlas 2026-09-23 17:08:20 +02:00
  • 596c0c17bc otel: back the hive collector off a failed bind instead of burning its start limit atlas 2026-09-23 12:55:56 +02:00
  • 2c066cc871 hive-c0re: pin the two security boundaries that had no test atlas 2026-09-23 17:00:44 +02:00