hyperhive/nix/host-modules
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 0649673ebf hive-tls: renew the swarm-services leaf on a daily timer
The store's `swarm-services` role issues the services leaf for 720h, and
`swarm-services-cert` only ever ran at boot or rebuild: it is a
`RemainAfterExit` oneshot wanted by `multi-user.target` and no timer
targeted it. A hive not rebuilt within 30 days served an expired leaf.

`swarm-services-cert-renew` runs the same script from a daily timer. It
is a unit of its own because a timer starting the `RemainAfterExit` unit
is a no-op, and restarting that unit instead would propagate through
`hive-gateway-self-signed-cert`'s `Requires=` to nginx, so a sealed store
would take the gateway down over a still-valid leaf. Nothing requires or
orders against the new unit; it has no `Restart=`, so a failure stays in
`systemctl --failed` until the next tick, and the script only moves files
into place after the store has answered.

The re-issue threshold was `checkend 2592000`, the whole 30-day
lifetime, so every run re-issued. It is now half the role's lifetime,
read from a new internal option `deploy.bao.servicesPkiLeafTtlHours`
that the role's `ttl`/`max_ttl` also read. Boot and timer share the
script and so the threshold. The services-root re-check reads the
same option, at the store's own replacement threshold (hours × 3600),
so the hive asks for a new leaf when the store replaces its root. A
`flock` keeps the two runs from interleaving one issuance's key with another's leaf.

`checks.module-eval-hive-tls` pins the timer, that the unit it starts
re-runs the issuance without `RemainAfterExit`, that nothing depends on
it, and that both the leaf and root thresholds move with the option.

Closes #4587
2026-09-25 23:38:36 +02:00
..
hive-c0re swarm-controller: own the swarm-wide forge objects; hive-c0re stops creating them 2026-09-25 08:36:05 +02:00
hive-forge swarm-controller: own the swarm-wide forge objects; hive-c0re stops creating them 2026-09-25 08:36:05 +02:00
hive-gateway nix: ship the journals of the units an apply can leave failed 2026-09-24 15:14:44 +02:00
lib swarm: extract the name guards, so the module just says what is forbidden 2026-08-31 18:50:15 +02:00
swarm-grafana/dashboards swarm-grafana: replace busiest-agents bargauges with an actual table 2026-09-20 23:40:21 +02:00
default.nix nix: run the forge on one host per swarm (deploy.forgejo.enable) 2026-09-24 23:56:07 +02:00
deploy.nix nix: run the forge on one host per swarm (deploy.forgejo.enable) 2026-09-24 23:56:07 +02:00
glue-bao-readers-policy-order.nix swarm-bao: give the store forwarder's OIDC reader its own bao identity 2026-09-25 00:37:31 +02:00
glue-bao-tls.nix swarm-bao: give the store forwarder's OIDC reader its own bao identity 2026-09-25 00:37:31 +02:00
glue-controller-bao-identity.nix swarm-controller: hand the daemon the authority hives are issued from 2026-09-10 00:25:07 +02:00
glue-forge-oidc-client.nix nix: run the forge on one host per swarm (deploy.forgejo.enable) 2026-09-24 23:56:07 +02:00
glue-grafana-oidc-client.nix nix: run the forge on one host per swarm (deploy.forgejo.enable) 2026-09-24 23:56:07 +02:00
glue-matrix-bao-token.nix nix: move the reader-after-policy edges into their own colocation glue 2026-09-24 15:15:15 +02:00
glue-matrix-ctl-bao-identity.nix swarm-matrix-ctl: one control binary for the matrix container, not one per job 2026-09-20 22:07:16 +02:00
glue-nats-bao-identity.nix swarm-nats: give the queue a name, a bao-issued leaf, and require TLS 2026-09-24 17:26:31 +02:00
glue-queue-agent-credential.nix nix: move the reader-after-policy edges into their own colocation glue 2026-09-24 15:15:15 +02:00
glue-secret-publisher-bao-identity.nix swarm: publish minted OIDC client secrets into the swarm store 2026-09-12 11:22:33 +02:00
glue-services-issuer-bao-identity.nix nix: issue the swarm-services leaf from bao's pki mount 2026-09-23 21:00:02 +02:00
glue-swarm-bao-otel-oidc-client.nix nix: the store's own collector scrapes its metrics listener 2026-09-21 17:19:52 +02:00
glue-swarm-otel-oidc-client.nix swarm-otel: deliver the OIDC client secret through the secret store 2026-09-14 00:58:58 +02:00
hive-ci.nix nix: run the forge on one host per swarm (deploy.forgejo.enable) 2026-09-24 23:56:07 +02:00
hive-matrix.nix hive-matrix: load the swarm's appservice and promote its sender 2026-09-25 08:31:01 +02:00
hive-network.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
hive-priv.nix docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
hive-tls.nix hive-tls: renew the swarm-services leaf on a daily timer 2026-09-25 23:38:36 +02:00
hyperhive.nix docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
local-defaults.nix swarm: default every queue URL to the queue's name on every hive 2026-09-24 17:26:31 +02:00
otel.nix otel.nix: trim the StartLimit comment block to the load-bearing points 2026-09-23 17:22:51 +02:00
stylix-theme.nix swarm-ui: apply the operator's stylix theme, same as the dashboard already does 2026-08-24 14:28:25 +02:00
swarm-authelia.nix nix: make swarm.authelia.url non-nullable, trim its docs 2026-09-21 18:14:28 +02:00
swarm-bao-bootstrap-policy.hcl swarm-bao: give the store forwarder's OIDC reader its own bao identity 2026-09-25 00:37:31 +02:00
swarm-bao.nix hive-tls: renew the swarm-services leaf on a daily timer 2026-09-25 23:38:36 +02:00
swarm-ca.nix nix: issue the swarm-services leaf from bao's pki mount 2026-09-23 21:00:02 +02:00
swarm-container-resolver.nix fix(#3363): swarm containers write their own resolver file 2026-08-17 17:30:15 +02:00
swarm-controller.nix swarm-controller: own the swarm-wide forge objects; hive-c0re stops creating them 2026-09-25 08:36:05 +02:00
swarm-grafana.nix nix: move the reader-after-policy edges into their own colocation glue 2026-09-24 15:15:15 +02:00
swarm-nats.nix swarm-nats: give the queue a name, a bao-issued leaf, and require TLS 2026-09-24 17:26:31 +02:00
swarm-otel.nix swarm-otel: correct the hostJournalDir comment for swarm-bao's exception 2026-09-25 04:02:08 +02:00
swarm-peers-removed.nix docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
swarm-required-services.nix nix: run the forge on one host per swarm (deploy.forgejo.enable) 2026-09-24 23:56:07 +02:00
swarm-secret-publisher.nix nix: the store's own collector scrapes its metrics listener 2026-09-21 17:19:52 +02:00
swarm-snapshot-store.nix deploy: move the wireguard mesh out of the namespace hives read 2026-09-07 14:24:52 +02:00
swarm-ui.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
swarm-victorialogs.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
swarm-victoriametrics.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
swarm-wireguard.nix deploy: move the wireguard mesh out of the namespace hives read 2026-09-07 14:24:52 +02:00
swarm.nix swarm-bao: give the store forwarder's OIDC reader its own bao identity 2026-09-25 00:37:31 +02:00