| Filename | Latest commit message | Latest commit date |
|---|---|---|
authelia now watches the users file, so the restart is redundant -- and it was the wrong shape twice over. It could fail: a login was refused for a user whose record was already correct on disk, with nothing in either log implicating the reload. And it only ever worked for this writer -- swarm-authelia-bridge writes the same file and cannot restart anything, since running unprivileged inside the container is the whole reason it may write it at all. A reload that depends on which process did the writing is not a reload. --machine/--unit and their two env vars existed solely to name a systemctl -M target, so they go with it. That drops two required settings from the operator surface. The three objections previously recorded against watch are all answered now, and are kept next to the decision rather than deleted: the key is verified against the pinned build (validate-config accepts it and rejects a misspelling), the watch is on the directory so a rename is observed, and partial reads are structurally impossible because every writer of this file goes through write_atomic. |
||
| .. | ||
| bash.md | ||
| forge.md | ||
| hivectl-cli.md | ||
| hivectl.md | ||
| lifecycle.md | ||
| matrix.md | ||
| README.md | ||
| scheduling.md | ||
| swarmctl-cli.md | ||
Tools
hivectl is your tool — the operator's own host CLI. Everything
else here documents the tool surface your agents get inside their
containers (the MCP tools an agent's own claude session can call).
You never call these directly, but they're the reference for what an
agent can actually do — useful when you're trying to understand or
debug agent behavior.
For the operator
- hivectl — the curated guide: provisioning forge and matrix accounts, gateway htpasswd management, container lifecycle shortcuts, interactive agent shell access.
- hivectl-cli — the exhaustive, auto-generated flag-by-flag reference, kept in lockstep with the binary by CI.
For the swarm operator
- swarmctl-cli — the exhaustive, auto-generated
flag-by-flag reference for
swarmctl, kept in lockstep with the binary by CI the same wayhivectl-cli.mdis.swarmctlitself runs as root on the swarm-controller host, not throughhivectl— seeswarmctl/README.mdfor why. No curated guide yet (one verb,user add, doesn't need one); add one here if/when that grows.
What your agents can do
- bash — background shell execution (
mcp__bash__*), available on every agent unconditionally. - forge — the
hive-forgeForgejo CLI every agent has for issues, PRs, and comments. Not an MCP tool — a binary agents shell out to instead of ad-hoc curl. - lifecycle — kill/start/restart/update for an agent's own direct children, plus the approval-gated config-change tools.
- matrix — the matrix MCP tool surface
(
mcp__matrix__*) for agents with a matrix account, multiple accounts per agent, and declaring extra MCP servers generally. - scheduling — scheduled prompts (operator
approval required) and the diagnostics tools (
get_logs,get_host_journal).