| Filename | Latest commit message | Latest commit date |
|---|---|---|
A swarm runs one homeserver and every hive on it logged in as the same `@hive:` localpart, holding the same access token out of one swarm-wide store path. That is one matrix identity for N hives: the homeserver cannot attribute an action to the hive that took it, and revoking one hive's standing revokes every hive's. Three changes, and the third is the one that makes the other two real: - **The localpart carries the hive's name** (`hive-<hive>`), derived in one place, `swarm_secret_client::matrix::hive_localpart`. `hive-matrix.nix` renders the same string as the appservice registration's `sender_localpart`, so the shared account stops being created rather than merely stops being used. - **The store path is templated by hive**, not a constant. The "a swarm runs one homeserver, so this is a constant rather than a parameter" rationale went with it; it stopped holding the moment two hives shared the homeserver it describes. - **The path moved out from under the grant every hive has.** It sat at `swarm/services/matrix/sender-token`, inside the `secret/data/swarm/services/*` read stanza `policy::render` gives every hive. It now sits under that hive's own stanza, `secret/data/swarm/hives/<hive>/*`, which interpolates the reader's name — so a hive reads its own token and is refused another's. The policy renderer itself is unchanged: narrowing the `services/*` grant would break the OIDC-secret read it exists for, and moving the credential is what this needed instead. A policy test walks the rendered stanzas and asserts none of hive alpha's covers hive beta's sender token, so a later stanza that widened it fails here. `swarm-matrix-ctl` takes a new required `MATRIX_MINT_HIVE` and writes that hive's path; its store grant in `swarm-bao.nix` follows, scoped to one hive's leaf via the new `deploy.bao.matrixCtlHiveName` (defaulting to this host's `hiveName`) rather than a `hives/*` wildcard, which would hand the matrix container every hive's token back. Migration: no outage at deploy. `ensure_hive_user` short-circuits on the local token file, so a hive keeps running on what it has; with no such file it reads the new per-hive path, finds nothing, and falls through to the existing register-or-appservice-login ladder against its own localpart — which needs only the per-hive `as_token` on local disk. The old shared object is read by nothing afterwards. Rooms do not follow the identity, and that is the one operator step; both ways out are written into `docs/integrations/matrix.md`. No admin standing is granted to the per-hive accounts: `admin_execute` stays empty and the assertion pinning it is untouched. |
||
| .. | ||
| agent-lifecycle | ||
| crates | ||
| getting-started | ||
| integrations | ||
| networking | ||
| process | ||
| scheduler | ||
| swarm | ||
| tools | ||
| trust-boundary | ||
| turn-loop | ||
| web-ui | ||
| README.md | ||
hyperhive docs
Depth reference for hyperhive — the substrate, not the pitch (that's the
top-level README / website).
Every page here stands alone; pick the one matching your task rather than
reading top to bottom. For the autogenerated NixOS options reference
(every services.hyperhive.* / hyperhive.* option, host and agent), see
the options site instead —
this tree is prose, that one's generated straight from the module
declarations.
Getting started
- Bringing a fresh hive online? →
getting-started/setup.md(first-runhivectlbootstrap). - What does the dashboard look like, and how do I use it? →
web-ui/— the operator-facing starting point; its own sub-pages (shape,dashboard,agent,css-vars,terminal-rendering) go deeper into implementation. - What tools does an agent (or the operator) have available? →
tools/—hivectl(yours) plus every agent's MCP tool surface (bash, forge, lifecycle, matrix, scheduling).
Agent lifecycle
- How do config changes flow from manager to operator to container? →
agent-lifecycle/approvals.md(approval kinds, approval state machine,flake.lockvalidation). - What state survives destroy / purge / restart? →
agent-lifecycle/persistence.md. - Who can do what to whom — agent hierarchy and privilege? →
agent-lifecycle/agent-hierarchy.md. - How does claude get its prompt, and what tools does it have? →
turn-loop/— the loop, binary shape, turn outcomes; sub-pages:claude-invocation,config,mcp.
Trust boundary & security
- What's the operator/agent trust boundary? What's a capability? →
trust-boundary/boundary.md. - Agent trust model, prompt-injection threat model, credential
isolation? →
trust-boundary/security.md.
Accounts & integrations
- How do per-agent forge accounts work? What does
forge_notifypoll, and how does it format wake messages? →integrations/forge.md(the hive's own Forgejo);tools/forge.mdfor thehive-forgeCLI verbs agents actually call. - How does the matrix-tuwunel container work? Multiple accounts per
agent? →
integrations/matrix.md(the homeserver);tools/matrix.mdfor the MCP tool surface andservices.hyperhive.agent.matrixAccounts. - How do I give an agent a GitHub account (
gh+git push)? how's the PAT injected? →integrations/github.md(operator content up top; thegh/git-push + notification-poller mechanics are in a collapsed "Implementation" section at the bottom). - What's
/knowledge? How does the hive-wide knowledge repo sync, and how do I contribute a document? →integrations/knowledge.md. - What does
hivectldo? Provisioning, gateway users, container shells? →tools/hivectl.md(the curated guide);tools/hivectl-cli.mdfor the exhaustive, autogenerated flag reference.
Networking & swarms
- What nginx vhosts does the gateway serve? How does matrix
discovery work? →
networking/gateway.md. - How does DNS resolution work in agent containers? What's the
bridge network for? →
networking/network.md. - How do I connect two hives into a swarm? →
swarm/(peer hives, TLS trust). - Where do agent snapshots go? How does the swarm's
btrfs receiveendpoint authenticate a pushing hive? →networking/snapshot-store.md. - Who mints each credential, who reads it, and how does it rotate — and
where's that shape headed? →
swarm/credentials.md(current state, target state, and the progressive-enhancement rule);swarm/secrets.mdfor where each file lives today.
Scheduler, CI, observability
- what's the job queue, as a general idea (not hive-c0re specifics)? →
scheduler/jobq.md— operator-facing, no implementation detail. - How does the rebuild queue work? What are the concrete step kinds,
queue sources, scheduler internals? →
scheduler/coordinator.md. - How does the CI runner work? What's the autoregistration flow? →
scheduler/ci.md. - How do I export Claude Code metrics (tokens, cost, tool calls) to
Prometheus/Grafana? →
scheduler/observability.md.
Crate reference
- What does a specific Rust crate do, on its own terms? →
crates/— every workspace crate's ownREADME.md, one level up from source; the crate itself is still the source of truth, this is just a walkable mirror.
Process & conventions
- Naming, commit style, wire protocol, the
data-asyncpattern? →process/conventions.md. - Why does the nspawn flag look like that? →
process/gotchas.md(bind mounts, conf flags, other NixOS/nspawn quirks). - What does a PR review verdict actually gate? →
process/pr-review-gate.md.