| Filename | Latest commit message | Latest commit date |
|---|---|---|
The gateway's nginx + dnsmasq no longer run in their own nspawn container. `nix/host-modules/hive-gateway/default.nix` loses the `containers.hive-gateway` wrapper and everything that existed only to punch holes in it: `privateNetwork = false`, `CAP_NET_ADMIN`, five bind mounts, its own `stateVersion`, `networking.firewall.enable = false`, `networking.resolvconf.enable = false`, and the `hive-gateway-resolv` path+service pair. 465 -> 303 lines. The container never bought isolation here. It shared the host netns by necessity — nginx binds the host's :80/:443, dnsmasq answers on the bridge — so each of those settings was undoing a boundary the gateway could not afford in the first place. Four things made it more than a deletion, none of them visible in the nix diff: - The self-signed cert service also imports the hive CA leaf, so removing it with the container would have left nginx naming a missing cert file, which it refuses to load at all. - The nginx reload is a hive-priv verb. It still needs root, but no longer for the reason its doc gave, and `--machine=` was both transport and scope — so the unit name is now hard-coded in the helper as the containment. - The lifecycle verb named a container that stops existing. - `journalctl -M hive-gateway` had no machine to enter. Per the operator's ruling, the operator verb keeps working and agents lose it. `InfraContainer` answered three questions that used to share an answer; it now splits into `name()` (identity), `target()` (Container vs HostUnit), `service_unit()` (the systemd unit), and `agent_restartable()`, which the MCP restart path checks before the capability so the refusal cannot read as "ask for infra_admin". `SIBLING_CONTAINERS` drops the gateway — it gates the requests that name a container as a string — while `FromStr` still accepts it, because that answers what a name is, not who may act on it. The dashboard's gateway journal reads host journald filtered to `nginx.service`. Prose was corrected where it only named a location, and re-argued where the container was doing security work: a `0666` per-agent socket was safe because only the gateway container had the directory bind-mounted. There is no mount now, so the directory permissions are the whole of the access control — the constraint holds, its mechanism doesn't. Gate: nix fmt / clippy --all-targets -D warnings / cargo test all clean (710 tests); hivectl-cli.md regenerated from the clap tree. The nix eval was run in both TLS shapes at this commit: every delta in the rendered virtualHosts is one of the three intended path moves, dnsmasq settings are byte-identical, and the absence probe flips true -> false with bindMounts emptied. |
||
| .. | ||
| agent.md | ||
| css-vars.md | ||
| dashboard.md | ||
| README.md | ||
| shape.md | ||
Dashboard & Web UI
The operator-facing entry point for running a hive day to day. If you want implementation detail — wire formats, DOM structure, event plumbing — see Dashboard layout, Per-agent page, Shape, and CSS theme variables below; this page only covers what you actually do here.
Where things are
Everything starts at the H0M3 hub, served at / — a grid of tiles
linking to every surface (Dashboard, Flow, Logs, Builds, Stats,
Settings, Core, Credentials, plus Matrix/Forge when enabled). Every
page links back to H0M3, so you're never more than one click from the
hub.
The dashboard itself (/dashboard.html) is where you'll spend most
of your time. It's a single page with exactly four tabs:
- SW4RM — every agent, live. This is the default tab and the one you'll check most. When the hive has peer hives configured, they show up here too, as a card list under the main container list — not a separate tab.
- Y3R C4LL — anything waiting on you: pending approvals and agent questions. If an agent needs a decision from you, it's here.
- P3RM1SS10NS — what tools and system-level access each agent has.
- SCH3DUL3S — scheduled prompts and agent self-reminders.
Everything else lives on its own page instead, all reachable from the
H0M3 hub: Flow (/flow.html, the raw live message stream across
the whole swarm), Logs (/logs.html, per-agent and host
journals), Stats (/stats.html, swarm-wide usage stats), Settings
(/settings.html, your local browser preferences), Builds (/builds.html, the rebuild
queue and build history), Core (/core.html, tombstones and
container resource use), and Credentials (/credentials.html,
provisioning matrix/GitHub/forge accounts per agent).
Each agent also has its own page — a full terminal view of that
agent's session, reachable by clicking its name anywhere in the
dashboard, or directly at /agent/<name>/ (or http://<host>:<port>/
if the gateway isn't in front).
The things you'll actually do
Check on an agent. SW4RM shows every container as a row: name,
whether it's running, what it's currently doing (a live status pill —
rebuilding…, starting…, and so on — while something's in flight),
and quick links (stats, screen, forge profile). Click the name to open
its terminal and watch it work in real time.
Answer something an agent is waiting on. Y3R C4LL is the one tab worth checking regularly — it's everything that needs you: approvals for config changes, and questions an agent has asked and is blocked on. The tab's count pill tells you at a glance if anything's pending.
Approve or reject a config change. Agent config changes (new packages, env vars, MCP servers) go through an approval queue rather than landing automatically — you'll see them on Y3R C4LL, with a diff of what's changing.
Start, stop, restart, or rebuild an agent. Select one or more
agents on SW4RM (click the icon) and use the selection bar, or use the
per-agent ⋮ menu on a single row. Rebuilding re-applies that agent's
current config; use it after approving a change, or whenever an agent
shows as "needs update."
Watch a build. BU1LDS shows the rebuild queue live, plus a streaming log of whatever's currently building. Useful right after approving a change or bumping a flake input.
Grant or revoke a tool/capability. P3RM1SS10NS is a checkbox matrix — rows are agents, columns are tool groups or capabilities. Nothing takes effect until you hit save all at the bottom of the tab; a save queues a rebuild for whichever agents actually changed.
Read an agent's logs. The Logs page's AGENT tab pulls a live
journald view for any agent + service; the per-agent ⋮ menu's
journal logs → link jumps straight there, pre-filtered.
Set up a schedule or check on a reminder. SCH3DUL3S covers both — recurring or one-shot prompts you schedule for one or more agents, and reminders agents have set for themselves.
Provision an account for an agent. The Credentials page covers Matrix, GitHub, and external-forge accounts per agent, without editing that agent's config repo.
More depth
- Dashboard layout — every tab and standalone page, in full implementation detail: endpoint shapes, event wiring, exact badge-derivation rules.
- Per-agent page — the per-agent terminal, composer, side panel, slash commands, and per-agent endpoints.
- Shape (shared by both) — the SPA skeleton, SSE multiplexing, and other plumbing shared across every page.
- CSS theme variables — the colour system, for anyone touching the frontend's CSS.