| Filename | Latest commit message | Latest commit date |
|---|---|---|
/etc/tmpfiles.d/hyperhive-agents.conf was a boot-time backstop (#2290) that pre-created every agent's bind sources. The start preamble already creates them for every c0re-driven start, and on this host only hive-c0re starts agent containers. The file was also the reason the socket dir's owner had to be declared there, which is how it spent its life at `0777 root root` whenever the uid could not be resolved (#4742). - hive-priv gains `EnsureAgentSocketDir { name }`, called from `set_nspawn_flags` in every start path. It creates `/run/hive-agent/<name>` `0751 root:root` with mkdirat relative to an O_DIRECTORY|O_NOFOLLOW fd for the parent. An existing entry has to be a directory (fstatat AT_SYMLINK_NOFOLLOW); anything else is refused, and a directory is left alone. hive-c0re's own create_dir_all went: its /run is read-only under ProtectSystem=strict. - The container's `hive-agent-user-migrate` activation chowns that dir to the agent user and sets 0751, the same way it already handles state/ and harness/. It refuses a symlink or non-directory there, since `test -d` and chmod follow links. No host-side passwd parse, and no window where the dir is world-writable. - `/run/hyperhive/agents/<name>` stays created by hive-c0re itself (`ensure_agent_runtime_dir`). It holds the `mcp.sock` that hive-c0re binds as hive-core, so it must not become root- or agent-owned. - The `/run/hive-agent` parent is declared in hive-priv.nix, `0755 root:root`, instead of hive-gateway's hive-core rule. hive-priv is its only writer now, and hive-priv's ReadWritePaths needs it to exist. - The manager start in `ensure_root_agent` now goes through `converge_start_preamble` + `start_with_fallback`. It was a bare start, so after a reboot the manager's bind sources existed only because of the tmpfiles file, and its limits drop-in did not exist at all. - Removed: `sync_tmpfiles`, `agent_uid_gid` / `parse_passwd_uid_gid`, `priv_client::sync_agent_tmpfiles`, `AgentTmpfilesEntry`, the tmpfiles body builder and their tests, plus the three call sites. - Legacy: hive-priv unlinks the file at every start, ignoring ENOENT. `SyncAgentTmpfiles` stays one release as a payload-ignoring variant that does the same unlink and returns Ok, for an older hive-c0re. Salvaged from #4752: the boundary.md correction that nginx only dials, because ProtectSystem=strict makes its /run read-only. Behaviour change: a manual `nixos-container start h-<name>` right after a reboot, before hive-c0re has started that agent, now fails on a missing bind source instead of starting. Closes #4742 |
||
| .. | ||
| agent-lifecycle | ||
| crates | ||
| getting-started | ||
| integrations | ||
| networking | ||
| process | ||
| scheduler | ||
| swarm | ||
| tools | ||
| trust-boundary | ||
| turn-loop | ||
| web-ui | ||
| README.md | ||
hyperhive docs
Depth reference for hyperhive — the substrate, not the pitch (that's the
top-level README / website).
Every page here stands alone; pick the one matching your task rather than
reading top to bottom. For the autogenerated NixOS options reference
(every services.hyperhive.* / hyperhive.* option, host and agent), see
the options site instead —
this tree is prose, that one's generated straight from the module
declarations.
Getting started
- Bringing a fresh hive online? →
getting-started/setup.md(first-runhivectlbootstrap). - What does the dashboard look like, and how do I use it? →
web-ui/— the operator-facing starting point; its own sub-pages (shape,dashboard,agent,css-vars,terminal-rendering) go deeper into implementation. - What tools does an agent (or the operator) have available? →
tools/—hivectl(yours) plus every agent's MCP tool surface (bash, forge, lifecycle, matrix, scheduling).
Agent lifecycle
- How do config changes flow from manager to operator to container? →
agent-lifecycle/approvals.md(approval kinds, approval state machine,flake.lockvalidation). - What state survives destroy / purge / restart? →
agent-lifecycle/persistence.md. - Who can do what to whom — the agent roster and privilege? →
agent-lifecycle/agent-hierarchy.md. - How does claude get its prompt, and what tools does it have? →
turn-loop/— the loop, binary shape, turn outcomes; sub-pages:claude-invocation,config,mcp.
Trust boundary & security
- What's the operator/agent trust boundary? What's a capability? →
trust-boundary/boundary.md. - Agent trust model, prompt-injection threat model, credential
isolation? →
trust-boundary/security.md.
Accounts & integrations
- How do per-agent forge accounts work? What does
forge_notifypoll, and how does it format wake messages? →integrations/forge.md(the hive's own Forgejo);tools/forge.mdfor thehive-forgeCLI verbs agents actually call. - How does the matrix-tuwunel container work? Multiple accounts per
agent? →
integrations/matrix.md(the homeserver);tools/matrix.mdfor the MCP tool surface andservices.hyperhive.agent.matrixAccounts. - How do I give an agent a GitHub account (
gh+git push)? how's the PAT injected? →integrations/github.md(operator content up top; thegh/git-push + notification-poller mechanics are in a collapsed "Implementation" section at the bottom). - What's
/knowledge? How does the hive-wide knowledge repo sync, and how do I contribute a document? →integrations/knowledge.md. - What does
hivectldo? Provisioning, gateway users, container shells? →tools/hivectl.md(the curated guide);tools/hivectl-cli.mdfor the exhaustive, autogenerated flag reference.
Networking & swarms
- What nginx vhosts does the gateway serve? How does matrix
discovery work? →
networking/gateway.md. - How does DNS resolution work in agent containers? What's the
bridge network for? →
networking/network.md. - How do I connect two hives into a swarm? →
swarm/(peer hives, TLS trust). - Where do agent snapshots go? How does the swarm's
btrfs receiveendpoint authenticate a pushing hive? →networking/snapshot-store.md. - Who mints each credential, who reads it, and how does it rotate — and
where's that shape headed? →
swarm/credentials.md(current state, target state, and the progressive-enhancement rule);swarm/secrets.mdfor where each file lives today.
Scheduler, CI, observability
- what's the job queue, as a general idea (not hive-c0re specifics)? →
scheduler/jobq.md— operator-facing, no implementation detail. - How does the rebuild queue work? What are the concrete step kinds,
queue sources, scheduler internals? →
scheduler/coordinator.md. - How does the CI runner work? What's the autoregistration flow? →
scheduler/ci.md. - How do I export Claude Code metrics (tokens, cost, tool calls) to
Prometheus/Grafana? →
scheduler/observability.md.
Crate reference
- What does a specific Rust crate do, on its own terms? →
crates/— every workspace crate's ownREADME.md, one level up from source; the crate itself is still the source of truth, this is just a walkable mirror.
Process & conventions
- Naming, commit style, wire protocol, the
data-asyncpattern? →process/conventions.md. - Why does the nspawn flag look like that? →
process/gotchas.md(bind mounts, conf flags, other NixOS/nspawn quirks). - What does a PR review verdict actually gate? →
process/pr-review-gate.md.