atlas
02f90b7bc6
swarm-bao: add a pki mount, role and issuing policy
...
First slice of the move off the hand-rolled swarm services sub-CA: the
store gains the three objects the eventual minter needs, and nothing
else.
- a `pki` secrets mount, enabled ask-first off the same `bao secrets
list` snapshot the kv-v2 mount beside it uses, so a rebuild that finds
it mounted does nothing;
- a `swarm-services` role on it, `allowed_domains` read straight out of
`swarm.serviceDomains` — the same swarm-tier list swarm-ca.nix
name-constrains its sub-CA to and hive-tls.nix carries as the leaf's
SANs — with subdomains, localhost, globs and IP SANs all off;
- a `swarm-services-issuer` policy granting `update` on
`pki/issue/swarm-services`.
Inert: the mount has no issuer generated into it, the role therefore
cannot issue, and no login role attaches the policy, so no token in the
swarm carries it. No consumer changes; swarm-ca.nix still mints the
services sub-CA exactly as before. Reversible with
`bao secrets disable pki`.
The cert-auth role that attaches the policy waits for the leaf carrying
its CN, which glue-bao-tls.nix mints — a later step.
Refs #4256
2026-09-17 14:01:38 +02:00
..
hive-c0re
swarm-logs: an agent's CLI for the swarm log store
2026-09-17 01:02:14 +02:00
hive-forge
forge: move the forgejo package to deploy — slice 10 complete
2026-09-07 20:46:38 +02:00
hive-gateway
docs: matrix gateway vhost defaults to chat.<swarm-domain>, not matrix.<domain>
2026-09-07 16:53:22 +02:00
lib
swarm: extract the name guards, so the module just says what is forbidden
2026-08-31 18:50:15 +02:00
swarm-grafana /dashboards
swarm-grafana: fix leaked test title on the agents dashboard
2026-09-14 00:21:23 +02:00
default.nix
swarm-otel: deliver the OIDC client secret through the secret store
2026-09-14 00:58:58 +02:00
deploy.nix
matrix: remove the registration token
2026-09-15 19:58:10 +02:00
glue-bao-tls.nix
swarm: publish minted OIDC client secrets into the swarm store
2026-09-12 11:22:33 +02:00
glue-controller-bao-identity.nix
swarm-controller: hand the daemon the authority hives are issued from
2026-09-10 00:25:07 +02:00
glue-grafana-oidc-client.nix
swarm-grafana: deliver the OIDC client secret through the secret store
2026-09-13 19:57:28 +02:00
glue-matrix-bao-token.nix
matrix: remove the registration token
2026-09-15 19:58:10 +02:00
glue-queue-agent-credential.nix
matrix: remove the registration token
2026-09-15 19:58:10 +02:00
glue-secret-publisher-bao-identity.nix
swarm: publish minted OIDC client secrets into the swarm store
2026-09-12 11:22:33 +02:00
glue-swarm-otel-oidc-client.nix
swarm-otel: deliver the OIDC client secret through the secret store
2026-09-14 00:58:58 +02:00
hive-ci.nix
deploy: split the forge's host decisions out of swarm.forge
2026-09-07 14:24:52 +02:00
hive-matrix.nix
matrix: publish the appservice token from the swarm, not just read it
2026-09-15 20:57:49 +02:00
hive-network.nix
docs: restructure into topic subdirectories, collapse duplicated index
2026-09-02 01:55:37 +02:00
hive-priv.nix
docs: restructure into topic subdirectories, collapse duplicated index
2026-09-02 01:55:37 +02:00
hive-tls.nix
docs: restructure into topic subdirectories, collapse duplicated index
2026-09-02 01:55:37 +02:00
hyperhive.nix
docs: restructure into topic subdirectories, collapse duplicated index
2026-09-02 01:55:37 +02:00
local-defaults.nix
bao: write the swarm controller's policy from inside the store
2026-09-07 18:43:09 +02:00
otel.nix
otel: scrape each collector's own loss counters
2026-09-12 10:34:06 +02:00
stylix-theme.nix
swarm-ui: apply the operator's stylix theme, same as the dashboard already does
2026-08-24 14:28:25 +02:00
swarm-authelia.nix
swarm-logs: an agent's CLI for the swarm log store
2026-09-17 01:02:14 +02:00
swarm-bao.nix
swarm-bao: add a pki mount, role and issuing policy
2026-09-17 14:01:38 +02:00
swarm-ca.nix
swarm-ca: state the store-is-world-readable rule once, not three times
2026-09-02 09:03:35 +02:00
swarm-container-resolver.nix
fix( #3363 ): swarm containers write their own resolver file
2026-08-17 17:30:15 +02:00
swarm-controller.nix
swarm-controller: add configured default matrix homeserver URL
2026-09-16 14:43:13 +02:00
swarm-grafana.nix
nix: inline the swarm sub-path aliases at their use sites
2026-09-13 20:02:20 +02:00
swarm-nats.nix
swarm: publish each agent's turn-state header on its own subject
2026-09-14 15:12:23 +02:00
swarm-otel.nix
swarm-otel: deliver the OIDC client secret through the secret store
2026-09-14 00:58:58 +02:00
swarm-peers-removed.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm-required-services.nix
deploy: rename enableAllLocalDefaults to deploy.singleHostSwarm
2026-08-30 20:12:16 +02:00
swarm-secret-publisher.nix
matrix: publish the appservice token from the swarm, not just read it
2026-09-15 20:57:49 +02:00
swarm-snapshot-store.nix
deploy: move the wireguard mesh out of the namespace hives read
2026-09-07 14:24:52 +02:00
swarm-ui.nix
swarm: move the controller's two packages to deploy
2026-09-07 20:46:38 +02:00
swarm-victorialogs.nix
nix: inline the swarm sub-path aliases at their use sites
2026-09-13 20:02:20 +02:00
swarm-victoriametrics.nix
nix: inline the swarm sub-path aliases at their use sites
2026-09-13 20:02:20 +02:00
swarm-wireguard.nix
deploy: move the wireguard mesh out of the namespace hives read
2026-09-07 14:24:52 +02:00
swarm.nix
swarm: say "no queue coordinates", never "a hive with no queue"
2026-09-13 11:13:17 +02:00