a swarm o agents, each in its own nspawn cage, gossiping over unix sockets. config changes flow as git commits, the operator approves them in a browser, every deploy is a tag. cyberpunk-themed dashboard included. 💜
  • Rust 68.7%
  • Nix 15.7%
  • JavaScript 8.4%
  • CSS 3.7%
  • TypeScript 1.9%
  • Other 1.6%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 08faa0970e swarm-otel: authenticate ingest per hive, and stamp the hive from the receiver
The swarm collector accepted OTLP from anyone who could reach it, and took
the `hive` resource attribute from the payload. So any writer on the swarm
network could attribute metrics to any hive, and nothing downstream could
tell.

The label now comes from which receiver accepted the sample: one receiver
per hive, each behind an `oidc` extension verifying a token minted for that
hive's audience, each feeding a pipeline whose `resource` processor upserts
a constant. A sender cannot influence it, because the only input is which
authenticated port the bytes arrived on.

That multiplicity is forced rather than preferred. A processor cannot read
the token's claims — `from_context` reads request metadata, and asking it
for an auth claim yields nothing, silently, with a healthy startup — and
one receiver holding several credentials never reveals which one matched.

The per-hive ports are internal: a hive reaches its receiver as a path
under this collector's existing gateway name, so nginx (rendered from this
same evaluation) is the only thing that names a port. Fronting each hive
with its own vhost would need a certificate, a DNS name and a gateway entry
per hive to express routing the gateway already does.

Turning this on removes the unauthenticated receiver. While an open port
still accepts samples the per-hive receivers are decoration, so this is the
switch itself rather than a hardening layer beside it; a swarm that wants
the open receiver says so.

`hive-ca-trust.nix` grows `bundlePathFor`, because a consumer taking its own
CA argument has to name the bundle rather than just have `SSL_CERT_FILE`
exported at it.
2026-08-19 15:27:09 +02:00
.forgejo/workflows docs: stop claiming tracker-tag/comment-block lint are non-required 2026-07-23 00:10:59 +02:00
branding docs(#1182): remove component-diagram.svg; trim README; link to website + options 2026-06-03 19:06:06 +02:00
claude-plugins skills(headless-screenshot): document two false-positive traps 2026-08-15 09:59:55 +02:00
docs docs(network): drop the otel reasoning instead of restating it 2026-08-19 02:04:57 +02:00
frontend swarm-ui: derive theme override from colors.css instead of duplicating hex values 2026-08-18 23:58:48 +02:00
hive-agent fix hint text per argus review: group into subdirs, not split into more top-level files 2026-08-18 22:07:05 +02:00
hive-agent-mcp reword ack->mark-done terminology on mark_todos_done and get_loose_ends 2026-08-16 17:55:33 +02:00
hive-agent-sock hive-agent: guarantee a wake after a self-requested /compact 2026-08-13 23:17:10 +02:00
hive-bash-mcp feat(#3245): gate rustdoc in nix flake check, and clear the workspace 2026-08-14 02:30:55 +02:00
hive-c0re test(hive-c0re): serialise the remaining env-mutating tests 2026-08-19 06:18:15 +02:00
hive-core-agent-sock hive-c0re/hivectl/hive-agent: pause as a job-queue DAG node (closes #3056) 2026-08-11 23:47:09 +02:00
hive-forge hive-forge: unit-test blocking_open_count 2026-08-19 15:17:28 +02:00
hive-forge-notify fix(hive-forge-notify): stop embedding the issue/PR description in todos 2026-08-16 23:39:54 +02:00
hive-host-sock fix(3179): the gateway's config files get their own state dir 2026-08-12 10:29:27 +02:00
hive-jobq feat(#3245): gate rustdoc in nix flake check, and clear the workspace 2026-08-14 02:30:55 +02:00
hive-jobq-wire address review: move parse_states/filter_nodes_by_state to hive-jobq-wire, rename placeholder enums, trim core-mirroring framing 2026-08-16 16:59:54 +02:00
hive-matrix-mcp feat(#3245): gate rustdoc in nix flake check, and clear the workspace 2026-08-14 02:30:55 +02:00
hive-metric cut the comments back to what the code cannot say 2026-08-14 23:16:59 +02:00
hive-priv hive-priv: replace json! with typed structs for account sidecar files 2026-08-13 23:16:17 +02:00
hive-priv-sock feat(#3245): gate rustdoc in nix flake check, and clear the workspace 2026-08-14 02:30:55 +02:00
hive-screen-mcp docs(#2627): add README for hive-screen-mcp 2026-07-23 14:17:47 +02:00
hive-sh4re feat(3088): move the gateway's nginx + dnsmasq onto the host 2026-08-11 18:01:03 +02:00
hive-sock-client feat(#3245): gate rustdoc in nix flake check, and clear the workspace 2026-08-14 02:30:55 +02:00
hive-types docs(#2627): add READMEs for the remaining infra crates 2026-07-23 13:16:29 +02:00
hivectl feat(#3245): gate rustdoc in nix flake check, and clear the workspace 2026-08-14 02:30:55 +02:00
nix swarm-otel: authenticate ingest per hive, and stamp the hive from the receiver 2026-08-19 15:27:09 +02:00
scripts scripts: cover .tsx in the tracker-tag and comment-block lints 2026-08-11 21:01:26 +02:00
swagger-ui-theme move swagger-ui-theme/ out of hive-c0re/ 2026-08-02 21:24:57 +02:00
swarm-authelia-bridge docs(#3422): the user store is one file, not two 2026-08-18 10:34:00 +02:00
swarm-authelia-bridge-sock add swarm-authelia-bridge: the only thing allowed to write swarm-authelia's users database 2026-08-16 22:38:40 +02:00
swarm-controller fix(#3458): add missing swarm_name field to test AppState initializer 2026-08-18 21:24:48 +02:00
swarm-nats-auth fix(#3363): grant the bare consumer-create subject the reader actually uses 2026-08-17 20:48:52 +02:00
swarm-queue-client fix(#3297): reject a publish template that names no hive 2026-08-17 17:34:27 +02:00
swarmctl chore(#3422): drop swarmctl's now-unused serde_json dependency 2026-08-18 10:40:36 +02:00
.gitignore fix(review): drop libnull.rlib artifact + add Errors doc to ensure_config_pr_webhook 2026-07-11 12:19:52 +02:00
.mailmap chore(#2165): add damocles@pr1ma + lexis@pr1ma mailmap entries 2026-07-04 13:50:16 +02:00
.prettierignore docs: give turn-loop/ a README.md landing page 2026-08-03 12:55:18 +02:00
.prettierrc temp: add prettier configs 2026-07-02 23:33:11 +02:00
Cargo.lock hive-forge: pin forgejo-api to 0.11.1 so it shares the workspace reqwest 2026-08-19 12:30:50 +02:00
Cargo.toml hive-forge: pin forgejo-api to 0.11.1 so it shares the workspace reqwest 2026-08-19 12:30:50 +02:00
CLAUDE.md docs(#3422): the user store is one file, not two 2026-08-18 10:34:00 +02:00
clippy.toml hivectl: wireguard mesh setup verbs (#1756) 2026-06-19 14:37:50 +02:00
flake.lock nix flake update 2026-07-13 13:58:53 +02:00
flake.nix wire swarm-authelia-bridge: systemd unit, oidc client, controller auth env 2026-08-16 22:38:40 +02:00
README.md docs(readme): drop Rust function-name citation for plain-language behavior 2026-08-15 12:45:22 +02:00

hyperhive

a swarm of claude-code agents, each in its own nspawn cage, gossiping over unix sockets. config changes flow as git commits, the operator approves them in a browser, every deploy is a tag. cyberpunk-themed dashboard included. 💜

Claude code is great in one window, exponentielle across many — but only if you can keep the agents from stepping on each other, give them durable identity, and stop them from eating production. hyperhive is the substrate.

  • identity = unix socket
  • communication = sqlite-backed broker (send / recv / ask / answer / remind)
  • config = git (manager proposes, operator approves, deploys land as tagged commits)
  • blast radius = container
host (NixOS, runs hive-c0re.service)
│
├── operator
│   ├── browser → :80 (hive-gateway)    dashboard + per-agent UIs
│   │                                   /agent/<name>/ → per-agent unix socket
│   └── CLI     → /run/hyperhive/host.sock   admin protocol
│
├── hive-c0re  (Rust daemon: lifecycle / broker / approvals /
│               auto-update / dashboard / sockets)
│
├── optional containers
│   ├── hive-gateway   nginx — proxies :80 → c0re dashboard + per-agent sockets
│   ├── hive-forge     Forgejo — per-agent accounts, config mirror (agent-configs/)
│   └── hive-matrix    tuwunel — Matrix homeserver + per-agent accounts
│
└── agent containers
    ├── h-ruth     manager (privileged MCP surface, approval gating)
    └── h-<name>   sub-agent (claude + MCP tools + per-agent web UI + unix socket)

→ website · → docs · → options reference

Depth lives in docs/ (rendered at hyperhive.darkest.space/docs/) — start at docs/README.md and pick the page matching your task rather than reading front to back.

Quick start

Minimal flake.nix for a host that runs hive-c0re:

{
  inputs = {
    nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";
    hyperhive.url = "git+https://forge.darkest.space/hyperhive/hyperhive";
    # Pin hyperhive to your own nixpkgs instead of the one it ships with
    # (see "Overriding nixpkgs" below) — recommended for most hosts:
    hyperhive.inputs.nixpkgs.follows = "nixpkgs";
  };

  outputs = { nixpkgs, hyperhive, ... }: {
    nixosConfigurations.my-host = nixpkgs.lib.nixosSystem {
      system = "x86_64-linux";
      modules = [
        hyperhive.nixosModules.default  # hive-c0re + hive-forge + hive-gateway in one import
        ({ ... }: {
          services.hyperhive.enable = true;
          # services.hyperhive.c0re.operatorPronouns = "they/them";  # default: "she/her"

          # ... rest of your host config
          system.stateVersion = "25.11";
        })
      ];
    };
  };
}

hive-c0re opens its admin socket + dashboard, auto-creates the manager container, and auto-rebuilds any container whose hyperhive rev goes stale. claude-code is unfree — hyperhive scopes the whitelist to itself, nothing for the operator to set.

Overriding nixpkgs

hyperhive pins its own nixpkgs so it builds standalone in CI. Add hyperhive.inputs.nixpkgs.follows = "nixpkgs" (as in the quick-start above) to build it against your host's nixpkgs instead — one less nixpkgs evaluation, no version drift from the rest of your system. Standard flake follows pattern; works as long as your channel is reasonably close to the nixos-26.05 hyperhive develops against. Drop it again if a much older/newer channel hits breakage hyperhive's CI doesn't catch.

For the full list of host and agent NixOS options see the options reference.

Operator CLI

hivectl is the operator-facing host CLI for ad-hoc administration that doesn't go through the broker (built alongside hive-c0re when the host module is enabled):

sudo hivectl forge create-user mara                       # provisions a forge user
sudo hivectl forge create-user mara --password 'hunter2'  # … with a fixed password
sudo hivectl matrix create-user mara                      # provisions a matrix user
sudo hivectl matrix create-user mara --password-stdin     # … reading one line from stdin

For a name that's a managed agent, hivectl persists the resulting token to that agent's state dir, the same as the boot sweep does. For a non-agent name (e.g. the operator's own forge/matrix account), it prints the token to stdout and writes nothing.

Build / deploy

nix develop -c cargo check
nix flake check        # rust + nix + toml fmt + clippy

# deploy from a host config that imports hyperhive.nixosModules.default
nix flake update --update-input hyperhive
sudo nixos-rebuild switch --flake .#<host>