hive-forge-notify grows a second binary, hive-github-notify. The two share the notification half of the job — tolerant parse, classification, formatting, dedupe, todo delivery — and nothing else: each binary owns its host's protocol outright. Two binaries rather than one multi-source daemon, and rather than a cargo feature. A feature would unify across the workspace and cost every crate its build cache. Two binaries keep the decision in nix: forge.nix installs the forge unit, github.nix installs the github one under hyperhive.github.enable, so a hive built without that module has no github poller in its closure at all — GitHub access is separable (a tier, a policy boundary), not merely switched off. Both binaries ship from the existing derivation, so packages.nix is untouched. The split is real at the code level too, not just at the unit level. source.rs is a trait; the impls live in the binaries that use them, so neither binary links the other's protocol code and the library names no host at all. The forge-only assigned-issue rollup moves into the forge binary for the same reason: it asks the forge what is assigned to this agent, which is not a notification-protocol concern. At runtime the github unit needs a PAT at <state>/github-token, the same dashboard-provisioned token the gh wrapper and the git credential helper already use. No PAT: it logs why and exits 0, which is why the unit is Restart=on-failure and not always. Forgejo's notifications API is modelled on GitHub's, so one tolerant parse serves both — the differences (string thread ids, PullRequest vs Pull) are absorbed by lenient deserializers rather than a second parse path. Thread ids normalise to String at the parse boundary; they are only ever opaque keys. Todo keys gain a per-source prefix so the two hosts cannot collide, and the forge's is deliberately empty to keep existing forge todo keys stable across the deploy that lands this. The github loop honours the server's X-Poll-Interval, re-arming only when the server asks for a slower cadence than ours; the hint is read before the status check, because it arrives on error and empty pages too and that is exactly when it matters. Reading the notification stream needs the notifications scope on the PAT, which a token minted for push access typically lacks; the failure mode is silence, so docs/github.md says so explicitly.
189 lines
6.4 KiB
Nix
189 lines
6.4 KiB
Nix
{
|
|
description = "hyperhive — multi-Claude-Code-agent orchestration on nixos-containers";
|
|
|
|
inputs = {
|
|
nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";
|
|
# Crane is stateless — no nixpkgs input to follow; `crane.mkLib
|
|
# pkgs` returns the lib at whatever pkgs we pass it (we use the
|
|
# project's pinned nixpkgs).
|
|
crane.url = "github:ipetkov/crane";
|
|
treefmt-nix = {
|
|
url = "github:numtide/treefmt-nix";
|
|
inputs.nixpkgs.follows = "nixpkgs";
|
|
};
|
|
};
|
|
|
|
# Thin entry point — the real logic lives under nix/:
|
|
# nix/sources.nix filtered source views (meta-flake + docs inputs)
|
|
# nix/rust.nix shared crane wiring (cleanSrc, cargoArtifacts)
|
|
# nix/packages/ every package output
|
|
# nix/checks.nix flake checks
|
|
# nix/devshell.nix dev shell
|
|
# nix/treefmt.nix formatter config
|
|
# nix/host-modules/, nix/agent-modules/, nix/templates/ the NixOS module trees
|
|
outputs =
|
|
inputs@{
|
|
self,
|
|
nixpkgs,
|
|
crane,
|
|
treefmt-nix,
|
|
}:
|
|
let
|
|
inherit (nixpkgs) lib;
|
|
systems = [
|
|
"aarch64-linux"
|
|
"x86_64-linux"
|
|
];
|
|
sources = import ./nix/sources.nix { inherit lib; };
|
|
forAllSystems =
|
|
f:
|
|
lib.genAttrs systems (
|
|
system:
|
|
f rec {
|
|
inherit system;
|
|
pkgs = nixpkgs.legacyPackages.${system};
|
|
treefmt-eval = treefmt-nix.lib.evalModule pkgs (import ./nix/treefmt.nix);
|
|
craneLib = crane.mkLib pkgs;
|
|
rust = import ./nix/rust.nix { inherit pkgs craneLib; };
|
|
}
|
|
);
|
|
in
|
|
{
|
|
packages = forAllSystems (
|
|
{
|
|
pkgs,
|
|
craneLib,
|
|
rust,
|
|
...
|
|
}:
|
|
import ./nix/packages {
|
|
inherit
|
|
pkgs
|
|
craneLib
|
|
rust
|
|
self
|
|
nixpkgs
|
|
;
|
|
}
|
|
);
|
|
|
|
nixosModules =
|
|
let
|
|
# Package wiring for agent containers — the harness modules
|
|
# consume hyperhive's own packages via the `hyperhive.packages`
|
|
# option (see nix/agent-modules/packages.nix); no overlay.
|
|
# The `mkDefault` is applied PER KEY (`mapAttrs`), not to the
|
|
# whole attrset: definition-level priority filtering runs
|
|
# before `attrsOf`'s per-key merge, so a whole-set `mkDefault`
|
|
# would be discarded entirely the moment an agent.nix
|
|
# overrides a single key. Per-key priorities make an
|
|
# individual override win while every other key keeps the
|
|
# flake default.
|
|
agentPackages =
|
|
{ lib, pkgs, ... }:
|
|
{
|
|
hyperhive.packages = lib.mapAttrs (_: lib.mkDefault) {
|
|
inherit (self.packages.${pkgs.stdenv.hostPlatform.system})
|
|
hive-agent
|
|
hive-agent-mcp
|
|
hive-bash-daemon
|
|
hive-forge
|
|
hive-forge-notify
|
|
hive-github-notify
|
|
hive-matrix-daemon
|
|
hive-metric
|
|
hive-screen-mcp
|
|
assets
|
|
frontend
|
|
reference-docs
|
|
claude-plugins
|
|
;
|
|
};
|
|
};
|
|
in
|
|
{
|
|
agent-base.imports = [
|
|
./nix/templates/agent.nix
|
|
agentPackages
|
|
];
|
|
ruth.imports = [
|
|
./nix/templates/ruth.nix
|
|
agentPackages
|
|
];
|
|
# The full host stack (nix/host-modules/default.nix aggregator) plus
|
|
# the package/source wiring from this flake. The wiring is a
|
|
# plain config module setting the `services.hyperhive.c0re.*`
|
|
# package options via `lib.mkDefault` — no overlay involved, and
|
|
# an operator override still wins. Intended usage:
|
|
#
|
|
# imports = [ hyperhive.nixosModules.default ];
|
|
# services.hyperhive.enable = true;
|
|
#
|
|
default =
|
|
{ lib, pkgs, ... }:
|
|
{
|
|
imports = [ ./nix/host-modules ];
|
|
services.hyperhive.c0re = {
|
|
package = lib.mkDefault self.packages.${pkgs.stdenv.hostPlatform.system}.default;
|
|
frontend = lib.mkDefault self.packages.${pkgs.stdenv.hostPlatform.system}.frontend;
|
|
assets = lib.mkDefault self.packages.${pkgs.stdenv.hostPlatform.system}.assets;
|
|
xdgIcons = lib.mkDefault self.packages.${pkgs.stdenv.hostPlatform.system}.xdg-icons;
|
|
hyperhiveFlake = lib.mkDefault "${sources.hyperhiveFlakeSource}";
|
|
# Narrow docs/ source, threaded as its own meta-flake input
|
|
# so doc edits don't re-hash the whole flake source.
|
|
hyperhiveDocs = lib.mkDefault "${sources.hyperhiveDocsSource}";
|
|
# Per-container toplevels — wired into
|
|
# `system.extraDependencies` when
|
|
# `services.hyperhive.c0re.preBuildAgentTemplates` is on so
|
|
# the host system closure pre-fetches the heavy build
|
|
# inputs. x86_64-linux only (nixosConfigurations are
|
|
# hardcoded to that system); the gate keeps aarch64 hosts
|
|
# from pulling them in via cross-build.
|
|
agentBaseToplevel = lib.mkDefault self.packages.x86_64-linux.agent-base-toplevel;
|
|
managerToplevel = lib.mkDefault self.packages.x86_64-linux.ruth-toplevel;
|
|
};
|
|
};
|
|
hive-ci = ./nix/host-modules/hive-ci.nix;
|
|
hive-forge = ./nix/host-modules/hive-forge;
|
|
};
|
|
|
|
nixosConfigurations =
|
|
let
|
|
mkContainer =
|
|
module:
|
|
nixpkgs.lib.nixosSystem {
|
|
system = "x86_64-linux";
|
|
modules = [ module ];
|
|
};
|
|
in
|
|
{
|
|
agent-base = mkContainer self.nixosModules.agent-base;
|
|
ruth = mkContainer self.nixosModules.ruth;
|
|
};
|
|
|
|
devShells = forAllSystems ({ pkgs, rust, ... }: import ./nix/devshell.nix { inherit pkgs rust; });
|
|
|
|
formatter = forAllSystems ({ treefmt-eval, ... }: treefmt-eval.config.build.wrapper);
|
|
|
|
checks = forAllSystems (
|
|
{
|
|
pkgs,
|
|
system,
|
|
treefmt-eval,
|
|
craneLib,
|
|
rust,
|
|
...
|
|
}:
|
|
import ./nix/checks.nix {
|
|
inherit
|
|
pkgs
|
|
craneLib
|
|
rust
|
|
self
|
|
system
|
|
treefmt-eval
|
|
;
|
|
}
|
|
);
|
|
};
|
|
}
|