Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/nix/agent-modules
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 97cf8a1b2b agent-modules: write bao's stderr where UMask=0377 lets it, name what failed
hive-agent-forge-token and hive-agent-queue-credential both run with
UMask=0377. Their scripts captured bao's stderr in `err="$(mktemp)"`,
which under that umask is created 0400; the very next `2>"$err"` on the
`bao login` line cannot reopen it for writing, so bash fails the
redirect with "Permission denied" before bao ever runs. The `if !`
around the login then took the only error branch it had and printed
"this agent's certificate was refused by the swarm secret store" — the
store was never contacted. No agent has fetched either credential.

The stderr file now lives in each unit's own 0700 RuntimeDirectory and
is removed before every redirect into it, so the redirect creates it —
the idiom forge-token.nix already used for its staging file.

The login's error branch now says which of these happened, then quotes
bao's output:
- `$err` could not be created, so bao never ran;
- the store answered with HTTP 4xx (refusal) or another status;
- the store sent a TLS alert rejecting the certificate;
- no answer at all (network, DNS, or local TLS).
Unreadable cert/key credentials are reported before bao runs.

bao.nix has the same fetch shape but no UMask=, so its mktemp file is
0600 and writable; it is untouched.

Closes #4735
2026-09-26 21:50:39 +02:00
..
agent-service.nix docs: retire the agent hierarchy from every page that described it 2026-09-21 22:08:47 +02:00
bao.nix swarm: courier an agent's store identity into its container, and log in with it 2026-09-19 01:55:31 +02:00
bash-env.nix nix: move the agent option namespace under services.hyperhive.agent 2026-09-17 20:19:30 +02:00
claude-settings.nix agent: make claudePlugins additive instead of replacing 2026-09-19 10:48:29 +02:00
dashboard-links.nix nix: move the agent option namespace under services.hyperhive.agent 2026-09-17 20:19:30 +02:00
default.nix agents: pull the forge token from bao; drop tea-login 2026-09-24 17:48:53 +02:00
docs.nix nix: move the agent option namespace under services.hyperhive.agent 2026-09-17 20:19:30 +02:00
forge-token.nix agent-modules: write bao's stderr where UMask=0377 lets it, name what failed 2026-09-26 21:50:39 +02:00
forge.nix agents: pull the forge token from bao; drop tea-login 2026-09-24 17:48:53 +02:00
frontend.nix nix: move the agent option namespace under services.hyperhive.agent 2026-09-17 20:19:30 +02:00
github.nix nix: move the agent option namespace under services.hyperhive.agent 2026-09-17 20:19:30 +02:00
logs.nix nix: move the agent option namespace under services.hyperhive.agent 2026-09-17 20:19:30 +02:00
matrix.nix hive-matrix-mcp: read the main account's token from the store too 2026-09-25 08:31:01 +02:00
mcp.nix agent-modules/mcp: give subagent daemon a longer default bash timeout 2026-09-21 17:20:59 +02:00
network.nix agents: pull the forge token from bao; drop tea-login 2026-09-24 17:48:53 +02:00
otel.nix otel: map journald PRIORITY onto a severity at every journald receiver 2026-09-20 14:23:56 +02:00
packages.nix nix: move the agent option namespace under services.hyperhive.agent 2026-09-17 20:19:30 +02:00
queue-identity.nix agent-modules: write bao's stderr where UMask=0377 lets it, name what failed 2026-09-26 21:50:39 +02:00
queue.nix swarm-nats: give the queue a name, a bao-issued leaf, and require TLS 2026-09-24 17:26:31 +02:00
renamed-options.nix matrix: drop the per-agent matrix.enable; accounts are the enable signal 2026-09-18 10:35:16 +02:00
screen.nix nix: move the agent option namespace under services.hyperhive.agent 2026-09-17 20:19:30 +02:00
user.nix host-modules: write credential files atomically; agent-modules: retry a failed .claude migration 2026-09-26 21:50:03 +02:00
weston-vnc.nix nix: move the agent option namespace under services.hyperhive.agent 2026-09-17 20:19:30 +02:00