Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/nix/script-tests
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas ccb5bd3b38 hive-agent: read the per-agent queue secret from bao in process
The harness now reads swarm/agents/<agent>/queue from the store itself,
under the agent's own store certificate, and holds it in memory only.
It reads once before the first connect and again on every reconnect
attempt (async-nats `ConnectOptions::with_auth_callback`), so an agent
whose secret was re-minted reconnects with the new value instead of
being refused until the container restarts.

hive-agent-queue-credential.service, the /run file it wrote, and
HIVE_AGENT_QUEUE_AGENT_SECRET_FILE are gone; queue-identity.nix now
hands hive-agent.service the store address, its certificate paths and
the agent name.

A failed or empty read before the first connect still falls back to
the hive's shared client. Each read is bounded by a 10s timeout, and
retries wait out the existing reconnect backoff (500ms doubling, capped
at 60s).

Closes #4783
2026-09-29 10:18:07 +02:00
..
agent-bao-fetch.nix hive-agent: read the per-agent queue secret from bao in process 2026-09-29 10:18:07 +02:00
agent-bao-fetch.sh hive-agent: read the per-agent queue secret from bao in process 2026-09-29 10:18:07 +02:00