atlas
22c96282b9
swarm-bao: re-run the operator viewer unit when the granter step succeeds
...
swarm-bao-operator-viewer-policy exits 0 while the granter may not
configure auth/oidc, so it never retries on its own. On 2026-09-29 the
operator fixed the granter (swarm-bao-granter-role succeeded at 15:29Z),
but the viewer unit had last run on 2026-09-28 19:11Z on that exit-0
branch. auth/oidc/config and the viewer role stayed unwritten and OIDC
login failed until a manual restart.
The granter unit now restarts the viewer unit from ExecStartPost, which
runs only after its script exits 0. Restart rather than start, because
the viewer unit is RemainAfterExit and a start would be a no-op.
--no-block, because the viewer unit is ordered after the granter and a
blocking restart would deadlock. The link is one-way, so the viewer's
own Restart=on-failure never re-runs the granter.
OnSuccess= would not fire (the granter stays active under
RemainAfterExit), and Wants=/PartOf= either no-op on an active unit or
also propagate a failed restart and every stop.
The viewer's log message no longer tells the operator to restart it.
Refs #4772
2026-09-29 17:45:58 +02:00
..
agent-forge-bao.nix
module-eval: pin the agent forge-token fetch and tea-login's removal
2026-09-24 17:48:53 +02:00
agent-icon.nix
nix: split module-eval into per-subsystem checks
2026-09-20 04:25:54 +02:00
agent-matrix.nix
hive-matrix-mcp: read the main account's token from the store too
2026-09-25 08:31:01 +02:00
agent-memory.nix
nix: split module-eval into per-subsystem checks
2026-09-20 04:25:54 +02:00
agent-otel.nix
module-eval: assert the severity table once, not once per tier
2026-09-20 14:23:56 +02:00
agent-plugins.nix
nix: split module-eval into per-subsystem checks
2026-09-20 04:25:54 +02:00
agent-queue-bao.nix
hive-agent: read the per-agent queue secret from bao in process
2026-09-29 10:18:07 +02:00
agent-user.nix
hive-priv: create agent socket dirs on start; drop hyperhive-agents.conf
2026-09-27 18:55:33 +02:00
bao-basics.nix
bao: serve the browser UI to admins via a loopback-only listener
2026-09-28 19:31:02 +02:00
bao-controller.nix
swarm-controller: read the queue client secret from the store, drop the file
2026-09-28 19:01:05 +02:00
bao-grants.nix
swarm-bao: re-run the operator viewer unit when the granter step succeeds
2026-09-29 17:45:58 +02:00
bao-matrix-reader.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
bao-otel-collector.nix
bao: serve the browser UI to admins via a loopback-only listener
2026-09-28 19:31:02 +02:00
core-toggle.nix
swarm-controller: read the queue client secret from the store, drop the file
2026-09-28 19:01:05 +02:00
forge-placement.nix
hive-forge: a first authelia login creates the forge account
2026-09-25 08:29:56 +02:00
grafana.nix
swarm-bao: stamp collector's service.name as "bao"
2026-09-25 08:30:25 +02:00
hive-otel.nix
swarm-bao: give the store's collector an explicit self-telemetry port
2026-09-23 18:04:33 +02:00
hive-tls.nix
swarm-bao: write every swarm-* grant as a bao granter, not with a 24h token
2026-09-27 22:57:46 +02:00
journald-severity.nix
module-eval: assert the severity table once, not once per tier
2026-09-20 14:23:56 +02:00
lib.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
matrix-core.nix
nix: split module-eval into per-subsystem checks
2026-09-20 04:25:54 +02:00
name-guards.nix
swarm-bao: write every swarm-* grant as a bao granter, not with a 24h token
2026-09-27 22:57:46 +02:00
nats-authelia.nix
swarm: let an agent publish its own icon
2026-09-28 13:47:37 +02:00
nats-tls.nix
swarm-controller: read the queue client secret from the store, drop the file
2026-09-28 19:01:05 +02:00
secret-publisher.nix
bao: OIDC login to the browser UI via authelia, as a metadata-only viewer
2026-09-28 19:56:38 +02:00
swarm-otel-core.nix
swarm-otel: bound the collector's restart backoff
2026-09-29 09:15:12 +02:00
swarm-otel-identity.nix
swarm-bao: refuse a remote reader that named seven of the eight leaves
2026-09-23 10:11:42 +02:00
swarm-services-switch.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00