atlas
2776e121e5
swarm-controller: mint each agent's matrix account with the swarm's token
...
A `MintAgentMatrixAccount` node creates the agent's account on the swarm's
homeserver with the swarm appservice token, stores its token at
`swarm/agents/<agent>/matrix/main`, and reads it back with whoami before
reporting success. It is a root of agent creation, `after_any` into the
deploy, and a five-minute backfill over every agent with a store identity
queues the same node — the shape of the forge-token mint.
The decision reads the stored token back rather than only checking that one
is stored: the swarm and a hive both pin the device `hyperhive-<agent>`, so
each login replaces the other's token. A failed read plans nothing, so an
outage never rotates every agent's token.
`matrixHomeserverUrl` now defaults to the swarm's `chat.` vhost, since the
mint is what consults it.
2026-09-25 08:31:01 +02:00
..
agent-forge-bao.nix
module-eval: pin the agent forge-token fetch and tea-login's removal
2026-09-24 17:48:53 +02:00
agent-icon.nix
nix: split module-eval into per-subsystem checks
2026-09-20 04:25:54 +02:00
agent-matrix.nix
nix: split module-eval into per-subsystem checks
2026-09-20 04:25:54 +02:00
agent-memory.nix
nix: split module-eval into per-subsystem checks
2026-09-20 04:25:54 +02:00
agent-otel.nix
module-eval: assert the severity table once, not once per tier
2026-09-20 14:23:56 +02:00
agent-plugins.nix
nix: split module-eval into per-subsystem checks
2026-09-20 04:25:54 +02:00
agent-queue-bao.nix
agent: fetch this agent's own swarm-queue credential from the store
2026-09-21 20:44:52 +02:00
bao-basics.nix
nix: split module-eval into per-subsystem checks
2026-09-20 04:25:54 +02:00
bao-controller.nix
swarm-controller: mint each agent's matrix account with the swarm's token
2026-09-25 08:31:01 +02:00
bao-grants.nix
hive-matrix: load the swarm's appservice and promote its sender
2026-09-25 08:31:01 +02:00
bao-matrix-reader.nix
hive-matrix: load the swarm's appservice and promote its sender
2026-09-25 08:31:01 +02:00
bao-otel-collector.nix
swarm-bao: stop linking the container's journal onto the host
2026-09-25 04:02:08 +02:00
core-toggle.nix
nix: run the forge on one host per swarm (deploy.forgejo.enable)
2026-09-24 23:56:07 +02:00
forge-placement.nix
hive-forge: a first authelia login creates the forge account
2026-09-25 08:29:56 +02:00
grafana.nix
swarm-bao: stamp collector's service.name as "bao"
2026-09-25 08:30:25 +02:00
hive-otel.nix
swarm-bao: give the store's collector an explicit self-telemetry port
2026-09-23 18:04:33 +02:00
journald-severity.nix
module-eval: assert the severity table once, not once per tier
2026-09-20 14:23:56 +02:00
lib.nix
module-eval: assert the severity table once, not once per tier
2026-09-20 14:23:56 +02:00
matrix-core.nix
nix: split module-eval into per-subsystem checks
2026-09-20 04:25:54 +02:00
name-guards.nix
swarm-bao: give the store forwarder's OIDC reader its own bao identity
2026-09-25 00:37:31 +02:00
nats-authelia.nix
nix: address the swarm IdP by its domain, not by who runs it
2026-09-21 18:14:28 +02:00
nats-tls.nix
swarm: default every queue URL to the queue's name on every hive
2026-09-24 17:26:31 +02:00
secret-publisher.nix
nix: the store's own collector scrapes its metrics listener
2026-09-21 17:19:52 +02:00
swarm-otel-core.nix
nix: ship the journals of the units an apply can leave failed
2026-09-24 15:14:44 +02:00
swarm-otel-identity.nix
swarm-bao: refuse a remote reader that named seven of the eight leaves
2026-09-23 10:11:42 +02:00
swarm-services-switch.nix
nix: split module-eval into per-subsystem checks
2026-09-20 04:25:54 +02:00