hyperhive/nix/host-modules
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 08faa0970e swarm-otel: authenticate ingest per hive, and stamp the hive from the receiver
The swarm collector accepted OTLP from anyone who could reach it, and took
the `hive` resource attribute from the payload. So any writer on the swarm
network could attribute metrics to any hive, and nothing downstream could
tell.

The label now comes from which receiver accepted the sample: one receiver
per hive, each behind an `oidc` extension verifying a token minted for that
hive's audience, each feeding a pipeline whose `resource` processor upserts
a constant. A sender cannot influence it, because the only input is which
authenticated port the bytes arrived on.

That multiplicity is forced rather than preferred. A processor cannot read
the token's claims — `from_context` reads request metadata, and asking it
for an auth claim yields nothing, silently, with a healthy startup — and
one receiver holding several credentials never reveals which one matched.

The per-hive ports are internal: a hive reaches its receiver as a path
under this collector's existing gateway name, so nginx (rendered from this
same evaluation) is the only thing that names a port. Fronting each hive
with its own vhost would need a certificate, a DNS name and a gateway entry
per hive to express routing the gateway already does.

Turning this on removes the unauthenticated receiver. While an open port
still accepts samples the per-hive receivers are decoration, so this is the
switch itself rather than a hardening layer beside it; a swarm that wants
the open receiver says so.

`hive-ca-trust.nix` grows `bundlePathFor`, because a consumer taking its own
CA argument has to name the bundle rather than just have `SSL_CERT_FILE`
exported at it.
2026-08-19 15:27:09 +02:00
..
hive-c0re fix(otel): let the SDK resolve hive-c0re's OTLP endpoint 2026-08-19 01:38:54 +02:00
hive-forge forge: pin issue search indexer to db, not bleve 2026-08-18 23:29:40 +02:00
hive-gateway docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
lib swarm-otel: authenticate ingest per hive, and stamp the hive from the receiver 2026-08-19 15:27:09 +02:00
default.nix feat(#3125): a swarm-tier OTEL collector, in its own container 2026-08-18 21:02:18 +02:00
hive-ci.nix feat(nix): move the forge host options under services.hyperhive.swarm 2026-08-05 03:44:53 +02:00
hive-matrix.nix feat(#3162): warn when a hive with an existing homeserver has not pinned serverName 2026-08-18 12:29:31 +02:00
hive-network.nix docs(network): drop the otel reasoning instead of restating it 2026-08-19 02:04:57 +02:00
hive-priv.nix fix(#2573): also add /etc/tmpfiles.d to hive-priv ReadWritePaths (same EROFS class) 2026-07-18 16:39:20 +02:00
hive-tls.nix fix(#3462): apply the name check in the unit that runs on the deploy 2026-08-18 21:54:38 +02:00
hyperhive.nix refactor(nix): a hive's domain comes out of the swarm directory 2026-08-05 22:43:17 +02:00
local-defaults.nix fix(#3343): move the all-local queue derivations into the deployment mode 2026-08-16 19:37:49 +02:00
otel.nix otel: build the hive tier's collector from contrib 2026-08-19 15:27:09 +02:00
swarm-authelia.nix swarm-authelia: give each hive client an audience and JWT access tokens 2026-08-19 15:27:09 +02:00
swarm-ca.nix fix(nix): a missing swarm-services leaf must not kill the whole gateway 2026-08-06 00:30:22 +02:00
swarm-container-resolver.nix fix(#3363): swarm containers write their own resolver file 2026-08-17 17:30:15 +02:00
swarm-controller.nix swarm-ui: show the swarm's name as the page title and top-left brand 2026-08-18 18:34:56 +02:00
swarm-grafana.nix fix(#3471): keep Metrics Drilldown, which declarativePlugins had silently removed 2026-08-18 22:40:59 +02:00
swarm-nats.nix fix(#3363): give the queue's auth responder the hive CA 2026-08-17 19:57:44 +02:00
swarm-otel.nix swarm-otel: authenticate ingest per hive, and stamp the hive from the receiver 2026-08-19 15:27:09 +02:00
swarm-peers-removed.nix docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
swarm-required-services.nix feat(#3125): reshape the hive-to-swarm OTEL hop by domain 2026-08-18 21:02:18 +02:00
swarm-snapshot-store.nix refactor(#2862): keep the option at services.hyperhive.snapshotStore 2026-07-31 19:03:24 +02:00
swarm-ui.nix feat(#3255): expose the controller's webhook endpoint through the swarm vhost 2026-08-18 12:28:09 +02:00
swarm-victoriametrics.nix fix(#3363): swarm containers write their own resolver file 2026-08-17 17:30:15 +02:00
swarm-wireguard.nix docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
swarm.nix fix(#3462): the swarm-services leaf never covered grafana, metrics or otel 2026-08-18 21:54:38 +02:00