hyperhive/docs
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 0e1a975f9f fix(3179): the gateway's config files get their own state dir
`agents.conf` and `gateway.htpasswd` move from /var/lib/hyperhive/gateway
to /var/lib/hive-gateway/conf, alongside the `tls/` the gateway already
kept there.

nginx reads both as an unprivileged user. Under c0re's state dir it could
only reach them by traversing a directory systemd re-declares `0750
hive-core` on every c0re start — so nginx was given `SupplementaryGroups
= [ "hive-core" ]`, which also handed it read access to everything else
group-readable in that tree. The tokens are individually 0600, but the
broker sqlite carries no explicit mode: every message between every agent
was readable by the process whose job is parsing untrusted network input.

Moving the files removes the need and the exposure together. The group is
gone, and its absence is now commented as load-bearing so it doesn't come
back as a fix for a symptom it would recreate.

Also drops this module's `/var/lib/hyperhive` tmpfiles rule. It declared
`0755 root root` and could never win against `StateDirectoryMode`, and a
losing declaration still reads as a guarantee — that is what sent the
first diagnosis of the outage looking for who had changed the mode.

Ordering is unchanged and still the thing that makes a fresh boot work:
tmpfiles runs before services and seeds both files empty-but-valid, nginx
names them (an `include` of a missing file is fatal, not empty), and
content arrives when c0re writes and reloads — which it does on every
topology change, so a boot against the empty seed resolves itself.

Folds in the mode fix: `write` now sets 0644 on the tmp file before the
rename, because a rename carries the source's mode and discards the
destination's, and the tmpfiles rule that declares 0644 is
create-if-absent so it never re-applies.
2026-08-12 10:29:27 +02:00
..
components docs: virtualize crate READMEs under docs/components/ 2026-08-11 20:32:05 +02:00
swarm docs(3186): the first user is required to start authelia, not to log in 2026-08-12 00:31:07 +02:00
tools fix(3179): the gateway's config files get their own state dir 2026-08-12 10:29:27 +02:00
turn-loop hive-agent: fix login-detection race with a fixed-baseline check (#3057) 2026-08-11 21:27:05 +02:00
web-ui web-ui: expose per-agent paused status, add pause/resume to the agent page's own overflow menu 2026-08-11 20:42:53 +02:00
agent-hierarchy.md docs: a config change is a PR from a clone, not an edit in place 2026-08-04 22:40:22 +02:00
approvals.md hive-sh4re: split manager-socket constants + HelperEvent into their own topic module 2026-08-10 23:05:18 +02:00
boundary.md docs(gateway): describe what is, not what changed 2026-08-11 18:09:51 +02:00
ci.md docs(ci): add a For operators section 2026-08-03 00:30:57 +02:00
conventions.md swarmctl: add CLI reference docs, same pattern as hivectl 2026-08-11 21:55:56 +02:00
coordinator.md feat(3088): move the gateway's nginx + dnsmasq onto the host 2026-08-11 18:01:03 +02:00
forge.md feat(#2642): a github.com notification poller alongside the forge one 2026-07-31 17:23:18 +02:00
gateway.md fix(3179): the gateway's config files get their own state dir 2026-08-12 10:29:27 +02:00
github.md docs(github): move impl detail below the operator-facing sections 2026-08-02 23:54:55 +02:00
gotchas.md feat(#2693): let the operator pin the claude-code every agent runs 2026-07-27 13:56:28 +02:00
knowledge.md docs: describe the knowledge-change broadcast in the sync-mechanism section 2026-08-02 03:13:04 +02:00
matrix.md feat(nix): the matrix server_name follows the swarm domain too 2026-08-09 17:32:44 +02:00
network.md docs(3083): getting into the SSO provider the first time 2026-08-11 23:30:44 +02:00
observability.md docs: name the swarm display name by its new path 2026-08-05 11:15:41 +02:00
persistence.md fix(#3044): stop mounting a child's harness dir into its parent 2026-08-10 20:28:09 +02:00
pr-review-gate.md docs: revise per review — no specific example, gate is per-repo config, soften auto-merge framing 2026-08-04 17:23:12 +02:00
README.md docs: virtualize crate READMEs under docs/components/ 2026-08-11 20:32:05 +02:00
security.md docs(gateway): describe what is, not what changed 2026-08-11 18:09:51 +02:00
setup.md docs(3186): the setup walkthrough gains the swarm SSO bootstrap 2026-08-12 10:06:37 +02:00
snapshot-store.md refactor(nix): swarm.peers becomes swarm.hives, a directory of every hive 2026-08-05 20:44:16 +02:00
terminal-rendering.md web-ui: remove dead ask->operator inline-answer binding from the per-agent terminal 2026-08-11 20:21:52 +02:00
web-ui.md docs(web-ui): add an operator-facing README as the subdir landing page 2026-08-02 23:26:29 +02:00

hyperhive docs

Depth reference for hyperhive — the substrate, not the pitch (that's the top-level README / website). Every page here stands alone; pick the one matching your task rather than reading top to bottom. For the auto-generated NixOS options reference (every services.hyperhive.* / hyperhive.* option, host and agent), see the options site instead — this tree is prose, that one's generated straight from the module declarations.

Getting started

  • Bringing a fresh hive online?setup.md (first-run hivectl bootstrap).
  • What does the dashboard look like, and how do I use it?web-ui/ — the operator-facing starting point; its own sub-pages (shape, dashboard, agent, css-vars) go deeper into implementation.
  • What tools does an agent (or the operator) have available?tools/hivectl (yours) plus every agent's MCP tool surface (bash, forge, lifecycle, matrix, scheduling).

Dashboard & agent UI internals

Turn loop, config, approvals

  • How does claude get its prompt, and what tools does it have?turn-loop/ — the loop, binary shape, turn outcomes; sub-pages: claude-invocation, config, mcp.
  • How do config changes flow from manager to operator to container?approvals.md (two-step spawn, approval state machine, flake.lock validation).
  • What state survives destroy / purge / restart?persistence.md.

Trust boundary & security

  • What's the operator/agent trust boundary? What's a capability?boundary.md.
  • Agent trust model, prompt-injection threat model, credential isolation?security.md.
  • Who can do what to whom — agent hierarchy and privilege?agent-hierarchy.md.

Accounts & integrations

  • How do per-agent forge accounts work? What does forge_notify poll, and how does it format wake messages?forge.md (the hive's own Forgejo); tools/forge.md for the hive-forge CLI verbs agents actually call.
  • How does the matrix-tuwunel container work? Multiple accounts per agent?matrix.md (the homeserver); tools/matrix.md for the MCP tool surface and hyperhive.matrixAccounts.
  • How do I give an agent a GitHub account (gh + git push)? How is the PAT injected?github.md.
  • What does hivectl do? Provisioning, gateway users, container shells?tools/hivectl.md (the curated guide); tools/hivectl-cli.md for the exhaustive, auto-generated flag reference.

Networking & swarms

  • What nginx vhosts does the gateway serve? How does matrix discovery work?gateway.md.
  • How does DNS resolution work in agent containers? What's the bridge network for?network.md.
  • How do I connect two hives into a swarm?swarm/ (peer hives, TLS trust).
  • Where do agent snapshots go? How does the swarm's btrfs receive endpoint authenticate a pushing hive?snapshot-store.md.

Scheduler, CI, observability

  • How does the rebuild queue work? What are queue kinds and sources?coordinator.md.
  • How does the CI runner work? What's the auto-registration flow?ci.md.
  • How do I export Claude Code metrics (tokens, cost, tool calls) to Prometheus/Grafana?observability.md.

Crate reference

  • What does a specific Rust crate do, on its own terms?components/ — every workspace crate's own README.md, one level up from source (hyperhive#3051); the crate itself is still the source of truth, this is just a walkable mirror.

Process & conventions

  • Naming, commit style, wire protocol, the data-async pattern?conventions.md.
  • Why does the nspawn flag look like that?gotchas.md (bind mounts, conf flags, other NixOS/nspawn quirks).
  • What is /knowledge? How does the hive-wide knowledge repo sync, and how do I contribute a document?knowledge.md.