hyperhive/nix/host-modules
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 3895a1e21d feat(#3517): register the swarm collector as an audienced oauth2 client
The forge's `/metrics` is published behind the gateway and denied to
everyone, waiting on a client to allow. This is that client.

An audience is a URL: authelia validates a bearer token against the
address being requested, and a client may only request an audience it is
registered for, so registration is the authorisation. The URLs are owned
by the services that publish them while audiences attach to one client,
so services contribute to a list and this module builds the single entry
— the `gateway.localNames` split, forced here by client definitions
concatenating rather than merging into a shared entry.

The access-control rule asks the client list whether the collector is
registered rather than re-deriving the conditions that register it. The
two drifting is not a build failure: authelia refuses a rule naming an
unknown client in its startup validator, so SSO fails to restart.
2026-08-24 13:35:14 +02:00
..
hive-c0re fix(otel): let the SDK resolve hive-c0re's OTLP endpoint 2026-08-19 01:38:54 +02:00
hive-forge feat(#3517): register the swarm collector as an audienced oauth2 client 2026-08-24 13:35:14 +02:00
hive-gateway docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
lib fix(#3527): a missing source must report as zero, not as empty 2026-08-19 20:27:00 +02:00
swarm-grafana/dashboards feat(#3494): provision the claude-usage dashboard 2026-08-23 23:21:50 +02:00
default.nix feat(#3125): a swarm-tier OTEL collector, in its own container 2026-08-18 21:02:18 +02:00
hive-ci.nix feat(nix): move the forge host options under services.hyperhive.swarm 2026-08-05 03:44:53 +02:00
hive-matrix.nix feat(#3162): warn when a hive with an existing homeserver has not pinned serverName 2026-08-18 12:29:31 +02:00
hive-network.nix docs(network): drop the otel reasoning instead of restating it 2026-08-19 02:04:57 +02:00
hive-priv.nix fix(#2573): also add /etc/tmpfiles.d to hive-priv ReadWritePaths (same EROFS class) 2026-07-18 16:39:20 +02:00
hive-tls.nix fix(#3462): apply the name check in the unit that runs on the deploy 2026-08-18 21:54:38 +02:00
hyperhive.nix refactor(nix): a hive's domain comes out of the swarm directory 2026-08-05 22:43:17 +02:00
local-defaults.nix fix(#3343): move the all-local queue derivations into the deployment mode 2026-08-16 19:37:49 +02:00
otel.nix feat(#3554): let a hive-owned service declare a scrape target 2026-08-23 22:45:56 +02:00
swarm-authelia.nix feat(#3517): register the swarm collector as an audienced oauth2 client 2026-08-24 13:35:14 +02:00
swarm-ca.nix fix(nix): a missing swarm-services leaf must not kill the whole gateway 2026-08-06 00:30:22 +02:00
swarm-container-resolver.nix fix(#3363): swarm containers write their own resolver file 2026-08-17 17:30:15 +02:00
swarm-controller.nix swarm-ui: show the swarm's name as the page title and top-left brand 2026-08-18 18:34:56 +02:00
swarm-grafana.nix feat(#3494): provision the claude-usage dashboard 2026-08-23 23:21:50 +02:00
swarm-nats.nix fix(#3363): give the queue's auth responder the hive CA 2026-08-17 19:57:44 +02:00
swarm-otel.nix feat(#3517): register the swarm collector as an audienced oauth2 client 2026-08-24 13:35:14 +02:00
swarm-peers-removed.nix docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
swarm-required-services.nix feat(#3125): reshape the hive-to-swarm OTEL hop by domain 2026-08-18 21:02:18 +02:00
swarm-snapshot-store.nix refactor(#2862): keep the option at services.hyperhive.snapshotStore 2026-07-31 19:03:24 +02:00
swarm-ui.nix swarm-ui: header profile menu — initials avatar, authelia settings + logout (#3570) 2026-08-24 00:01:30 +02:00
swarm-victoriametrics.nix feat(swarm-victoriametrics): scrape the store's own prometheus endpoint 2026-08-19 21:40:40 +02:00
swarm-wireguard.nix docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
swarm.nix fix(#3462): the swarm-services leaf never covered grafana, metrics or otel 2026-08-18 21:54:38 +02:00