Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/nix/host-modules
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 1d261b3fed swarm-nats: give the queue a name, a bao-issued leaf, and require TLS
The queue listened in plaintext on 4222, reached by bridge IP or loopback,
and nothing in-tree opened it to another hive. It now has a name, serves a
certificate for that name alone, and refuses clients that do not speak TLS.

- `swarm.nats.domain`, default `nats.<swarm.domain>`, a sibling name like
  `swarm.bao.domain`. The queue host answers it via `gateway.localNames`;
  every other hive resolves it through the operator's DNS, as for bao.
- `pki/roles/swarm-nats` allows that one name (bare domain, no subdomains,
  IPs or localhost, server flag). A `swarm-nats` cert-auth role and policy
  may only `update` `pki/issue/swarm-nats`, written by
  `swarm-bao-nats-tls-policy`. The login leaf is minted by glue-bao-tls and
  paired by glue-nats-bao-identity. `deploy.bao.natsCommonName` is reserved
  as a hive name.
- `swarm-bao-nats-tls` issues the leaf into a directory bound read-only into
  the container, restarts nats when it rotates, and re-runs daily.
  It joins glue-bao-readers-policy-order, so it is ordered after its policy
  unit (`after` and `wants`, never `requires`) where the store is on the
  same host. The policy unit joins the store's journald list.
- nats gets `tls {}`, with the key via `LoadCredential`, and no
  `allow_non_tls`. `validateConfig` is now off in every mode, because the
  build-time check loads a leaf that only exists at runtime.
- 4222 is also open on `wg-hive` when the host is on the mesh, never
  host-wide.
- `statusPublish.natsUrl`, `queue.agentNatsUrl`, the controller's URL under
  `singleHostSwarm`, and the auth responder all dial
  `tls://<swarm.nats.domain>:<port>`. swarm-queue-client hands its CA file
  to the NATS connection too, so hive-c0re and the controller trust the
  leaf's root.
- docs/swarm/README.md: the queue URL and the one DNS record a multi-host
  swarm needs.

module-eval-nats-tls pins the role, the policy, the served leaf, the
firewall, the ordering, and a scan of every `*_NATS_URL` and the
responder's URL across the host and its containers.

Closes #4626
2026-09-24 17:26:31 +02:00
..
hive-c0re swarm-nats: give the queue a name, a bao-issued leaf, and require TLS 2026-09-24 17:26:31 +02:00
hive-forge nix: make swarm.authelia.url non-nullable, trim its docs 2026-09-21 18:14:28 +02:00
hive-gateway nix: ship the journals of the units an apply can leave failed 2026-09-24 15:14:44 +02:00
lib swarm: extract the name guards, so the module just says what is forbidden 2026-08-31 18:50:15 +02:00
swarm-grafana/dashboards swarm-grafana: replace busiest-agents bargauges with an actual table 2026-09-20 23:40:21 +02:00
default.nix swarm-nats: give the queue a name, a bao-issued leaf, and require TLS 2026-09-24 17:26:31 +02:00
deploy.nix swarm-controller: make socketPath readOnly instead of asserting it 2026-09-17 19:27:30 +02:00
glue-bao-readers-policy-order.nix swarm-nats: give the queue a name, a bao-issued leaf, and require TLS 2026-09-24 17:26:31 +02:00
glue-bao-tls.nix swarm-nats: give the queue a name, a bao-issued leaf, and require TLS 2026-09-24 17:26:31 +02:00
glue-controller-bao-identity.nix swarm-controller: hand the daemon the authority hives are issued from 2026-09-10 00:25:07 +02:00
glue-grafana-oidc-client.nix swarm-grafana: deliver the OIDC client secret through the secret store 2026-09-13 19:57:28 +02:00
glue-matrix-bao-token.nix nix: move the reader-after-policy edges into their own colocation glue 2026-09-24 15:15:15 +02:00
glue-matrix-ctl-bao-identity.nix swarm-matrix-ctl: one control binary for the matrix container, not one per job 2026-09-20 22:07:16 +02:00
glue-nats-bao-identity.nix swarm-nats: give the queue a name, a bao-issued leaf, and require TLS 2026-09-24 17:26:31 +02:00
glue-queue-agent-credential.nix nix: move the reader-after-policy edges into their own colocation glue 2026-09-24 15:15:15 +02:00
glue-secret-publisher-bao-identity.nix swarm: publish minted OIDC client secrets into the swarm store 2026-09-12 11:22:33 +02:00
glue-services-issuer-bao-identity.nix nix: issue the swarm-services leaf from bao's pki mount 2026-09-23 21:00:02 +02:00
glue-swarm-bao-otel-oidc-client.nix nix: the store's own collector scrapes its metrics listener 2026-09-21 17:19:52 +02:00
glue-swarm-otel-oidc-client.nix swarm-otel: deliver the OIDC client secret through the secret store 2026-09-14 00:58:58 +02:00
hive-ci.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
hive-matrix.nix nix: make swarm.authelia.url non-nullable, trim its docs 2026-09-21 18:14:28 +02:00
hive-network.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
hive-priv.nix docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
hive-tls.nix nix: ship the journals of the units an apply can leave failed 2026-09-24 15:14:44 +02:00
hyperhive.nix docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
local-defaults.nix swarm-nats: give the queue a name, a bao-issued leaf, and require TLS 2026-09-24 17:26:31 +02:00
otel.nix otel.nix: trim the StartLimit comment block to the load-bearing points 2026-09-23 17:22:51 +02:00
stylix-theme.nix swarm-ui: apply the operator's stylix theme, same as the dashboard already does 2026-08-24 14:28:25 +02:00
swarm-authelia.nix nix: make swarm.authelia.url non-nullable, trim its docs 2026-09-21 18:14:28 +02:00
swarm-bao-bootstrap-policy.hcl swarm-bao: keep the bootstrap policy in one file, checked against the units using it (#4698) 2026-09-24 15:55:38 +02:00
swarm-bao.nix swarm-nats: give the queue a name, a bao-issued leaf, and require TLS 2026-09-24 17:26:31 +02:00
swarm-ca.nix nix: issue the swarm-services leaf from bao's pki mount 2026-09-23 21:00:02 +02:00
swarm-container-resolver.nix fix(#3363): swarm containers write their own resolver file 2026-08-17 17:30:15 +02:00
swarm-controller.nix swarm-nats: give the queue a name, a bao-issued leaf, and require TLS 2026-09-24 17:26:31 +02:00
swarm-grafana.nix nix: move the reader-after-policy edges into their own colocation glue 2026-09-24 15:15:15 +02:00
swarm-nats.nix swarm-nats: give the queue a name, a bao-issued leaf, and require TLS 2026-09-24 17:26:31 +02:00
swarm-otel.nix swarm-nats: give the queue a name, a bao-issued leaf, and require TLS 2026-09-24 17:26:31 +02:00
swarm-peers-removed.nix docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
swarm-required-services.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
swarm-secret-publisher.nix nix: the store's own collector scrapes its metrics listener 2026-09-21 17:19:52 +02:00
swarm-snapshot-store.nix deploy: move the wireguard mesh out of the namespace hives read 2026-09-07 14:24:52 +02:00
swarm-ui.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
swarm-victorialogs.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
swarm-victoriametrics.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
swarm-wireguard.nix deploy: move the wireguard mesh out of the namespace hives read 2026-09-07 14:24:52 +02:00
swarm.nix swarm-nats: give the queue a name, a bao-issued leaf, and require TLS 2026-09-24 17:26:31 +02:00