hyperhive/nix/module-eval
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 0649673ebf hive-tls: renew the swarm-services leaf on a daily timer
The store's `swarm-services` role issues the services leaf for 720h, and
`swarm-services-cert` only ever ran at boot or rebuild: it is a
`RemainAfterExit` oneshot wanted by `multi-user.target` and no timer
targeted it. A hive not rebuilt within 30 days served an expired leaf.

`swarm-services-cert-renew` runs the same script from a daily timer. It
is a unit of its own because a timer starting the `RemainAfterExit` unit
is a no-op, and restarting that unit instead would propagate through
`hive-gateway-self-signed-cert`'s `Requires=` to nginx, so a sealed store
would take the gateway down over a still-valid leaf. Nothing requires or
orders against the new unit; it has no `Restart=`, so a failure stays in
`systemctl --failed` until the next tick, and the script only moves files
into place after the store has answered.

The re-issue threshold was `checkend 2592000`, the whole 30-day
lifetime, so every run re-issued. It is now half the role's lifetime,
read from a new internal option `deploy.bao.servicesPkiLeafTtlHours`
that the role's `ttl`/`max_ttl` also read. Boot and timer share the
script and so the threshold. The services-root re-check reads the
same option, at the store's own replacement threshold (hours × 3600),
so the hive asks for a new leaf when the store replaces its root. A
`flock` keeps the two runs from interleaving one issuance's key with another's leaf.

`checks.module-eval-hive-tls` pins the timer, that the unit it starts
re-runs the issuance without `RemainAfterExit`, that nothing depends on
it, and that both the leaf and root thresholds move with the option.

Closes #4587
2026-09-25 23:38:36 +02:00
..
agent-forge-bao.nix module-eval: pin the agent forge-token fetch and tea-login's removal 2026-09-24 17:48:53 +02:00
agent-icon.nix nix: split module-eval into per-subsystem checks 2026-09-20 04:25:54 +02:00
agent-matrix.nix hive-matrix-mcp: read the main account's token from the store too 2026-09-25 08:31:01 +02:00
agent-memory.nix nix: split module-eval into per-subsystem checks 2026-09-20 04:25:54 +02:00
agent-otel.nix module-eval: assert the severity table once, not once per tier 2026-09-20 14:23:56 +02:00
agent-plugins.nix nix: split module-eval into per-subsystem checks 2026-09-20 04:25:54 +02:00
agent-queue-bao.nix agent: fetch this agent's own swarm-queue credential from the store 2026-09-21 20:44:52 +02:00
bao-basics.nix nix: split module-eval into per-subsystem checks 2026-09-20 04:25:54 +02:00
bao-controller.nix swarm-controller: mint each agent's matrix account with the swarm's token 2026-09-25 08:31:01 +02:00
bao-grants.nix hive-matrix: load the swarm's appservice and promote its sender 2026-09-25 08:31:01 +02:00
bao-matrix-reader.nix hive-matrix: load the swarm's appservice and promote its sender 2026-09-25 08:31:01 +02:00
bao-otel-collector.nix swarm-bao: stop linking the container's journal onto the host 2026-09-25 04:02:08 +02:00
core-toggle.nix nix: run the forge on one host per swarm (deploy.forgejo.enable) 2026-09-24 23:56:07 +02:00
forge-placement.nix hive-forge: a first authelia login creates the forge account 2026-09-25 08:29:56 +02:00
grafana.nix swarm-bao: stamp collector's service.name as "bao" 2026-09-25 08:30:25 +02:00
hive-otel.nix swarm-bao: give the store's collector an explicit self-telemetry port 2026-09-23 18:04:33 +02:00
hive-tls.nix hive-tls: renew the swarm-services leaf on a daily timer 2026-09-25 23:38:36 +02:00
journald-severity.nix module-eval: assert the severity table once, not once per tier 2026-09-20 14:23:56 +02:00
lib.nix module-eval: assert the severity table once, not once per tier 2026-09-20 14:23:56 +02:00
matrix-core.nix nix: split module-eval into per-subsystem checks 2026-09-20 04:25:54 +02:00
name-guards.nix swarm-bao: give the store forwarder's OIDC reader its own bao identity 2026-09-25 00:37:31 +02:00
nats-authelia.nix nix: address the swarm IdP by its domain, not by who runs it 2026-09-21 18:14:28 +02:00
nats-tls.nix swarm: default every queue URL to the queue's name on every hive 2026-09-24 17:26:31 +02:00
secret-publisher.nix nix: the store's own collector scrapes its metrics listener 2026-09-21 17:19:52 +02:00
swarm-otel-core.nix nix: ship the journals of the units an apply can leave failed 2026-09-24 15:14:44 +02:00
swarm-otel-identity.nix swarm-bao: refuse a remote reader that named seven of the eight leaves 2026-09-23 10:11:42 +02:00
swarm-services-switch.nix module-eval: give the forgejo-mirror fixtures deploy.forgejo.enable 2026-09-25 08:36:05 +02:00