# swarm-matrix-ctl The rust that runs **inside `containers.hive-matrix`**, beside the homeserver. One binary with subcommands rather than one binary per job. Running code in that container is not free: it needs its own store identity, its own cert role and its own bind mounts, and every one of those is per-_container_, not per-task. A second single-purpose crate would have had to duplicate that plumbing to add one action, so the next thing that has to run in here is a **verb**, not a new crate. ## Verbs ### `appservice render` Mints the swarm appservice registration's tokens when absent and renders the registration tuwunel loads. Runs before the homeserver and needs no network. ### `appservice publish` Writes the rendered `as_token` to the swarm secret store for `swarm-controller`, when the store's copy differs. Both are configured entirely by the `MATRIX_APPSERVICE_*` environment the units set — no flags. A systemd `Environment=` block is what a nix module can render; a command line full of paths is not. ## 🩸 A secret is a path, never a value Nothing here logs, prints or interpolates a token. The one identifier this binary logs is the store path it wrote.