atlas
3898ca33c7
bao: serve the browser UI to admins via a loopback-only listener
...
openbao gains a second listener, `ui`, on 127.0.0.1:<deploy.bao.uiPort>
(default 8204) with TLS off and no client-certificate requirement, and
`ui = true`. The existing listeners are unchanged. An nginx inside the
store's container, on 127.0.0.1:<deploy.bao.uiProxyPort> (default 8206),
forwards only /ui/ and /v1/ to it, redirects / to /ui/, answers 403 on
sys/unseal, sys/seal, sys/step-down, sys/rekey* and sys/generate-root*,
and 404 on everything else.
The gateway on the store's host serves `swarm.bao.ui.domain` (default
bao-ui.<swarm>) behind the authelia auth_request subrequest, proxying to
that nginx; the name joins serviceDomains and localNames like every
other gateway-published swarm service. authelia gets an access_control
rule restricting that name to group:admins, rendered wherever authelia
runs, since the default policy admits any session.
Trade-off, ruled by the operator on the parent issue: the UI listener
asks for no client certificate, so on that door a bao token alone is the
credential.
Three comments and a doc line claimed every API listener demands a
client certificate; they now except the loopback UI listener. The
module-eval case counting declared listeners excludes `ui` by name, as
it already did `metrics`.
On a self-signed gateway, the UI's name is a swarm service name, so its
host requests the services leaf from the store. `swarm-services-cert`
sits Before= and RequiredBy= the gateway's cert import, which nginx
Requires=. On a host whose only swarm name is the UI, that would hold
nginx, and with it the stream passthrough every reader dials, on a login
to a store that may be sealed. hive-tls drops those two edges exactly
when the UI is the only local swarm name: nginx starts on the existing
hive-leaf fallback, and the script's existing re-import reloads nginx
once the leaf issues. Every other host keeps both edges.
2026-09-28 19:31:02 +02:00
..
hive-c0re
hive-priv: create agent socket dirs on start; drop hyperhive-agents.conf
2026-09-27 18:55:33 +02:00
hive-forge
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
hive-gateway
hive-priv: create agent socket dirs on start; drop hyperhive-agents.conf
2026-09-27 18:55:33 +02:00
lib
lint: tighten atomic-write-secret.nix's header comment; fix vale contractions in persistence.md
2026-09-26 21:50:03 +02:00
swarm-grafana /dashboards
swarm-grafana: revert busiest-agents table, restore bargauges ( #4658 )
2026-09-28 11:52:33 +02:00
bao-bootstrap-policy.hcl
swarm-bao: write every swarm-* grant as a bao granter, not with a 24h token
2026-09-27 22:57:46 +02:00
default.nix
swarm-nats-auth: verify an agent's own token against the store
2026-09-28 08:24:52 +02:00
deploy.nix
swarm-controller: read the queue client secret from the store, drop the file
2026-09-28 19:01:05 +02:00
glue-bao-readers-policy-order.nix
swarm-bao: write every swarm-* grant as a bao granter, not with a 24h token
2026-09-27 22:57:46 +02:00
glue-bao-tls.nix
swarm-nats-auth: verify an agent's own token against the store
2026-09-28 08:24:52 +02:00
glue-controller-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-forge-oidc-client.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-grafana-oidc-client.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-matrix-bao-token.nix
host-modules: atomic_write_secret takes the value as an argument, not stdin
2026-09-26 21:50:03 +02:00
glue-matrix-ctl-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-nats-auth-bao-identity.nix
swarm-nats-auth: verify an agent's own token against the store
2026-09-28 08:24:52 +02:00
glue-nats-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-queue-agent-credential.nix
host-modules: atomic_write_secret takes the value as an argument, not stdin
2026-09-26 21:50:03 +02:00
glue-secret-publisher-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-services-issuer-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-swarm-bao-otel-oidc-client.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-swarm-otel-oidc-client.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
hive-ci.nix
nix: run the forge on one host per swarm (deploy.forgejo.enable)
2026-09-24 23:56:07 +02:00
hive-matrix.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
hive-network.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
hive-priv.nix
hive-priv: create agent socket dirs on start; drop hyperhive-agents.conf
2026-09-27 18:55:33 +02:00
hive-tls.nix
bao: serve the browser UI to admins via a loopback-only listener
2026-09-28 19:31:02 +02:00
hyperhive.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
local-defaults.nix
swarm-controller: read the queue client secret from the store, drop the file
2026-09-28 19:01:05 +02:00
otel.nix
otel.nix: trim the StartLimit comment block to the load-bearing points
2026-09-23 17:22:51 +02:00
stylix-theme.nix
swarm-ui: apply the operator's stylix theme, same as the dashboard already does
2026-08-24 14:28:25 +02:00
swarm-authelia.nix
bao: serve the browser UI to admins via a loopback-only listener
2026-09-28 19:31:02 +02:00
swarm-bao.nix
bao: serve the browser UI to admins via a loopback-only listener
2026-09-28 19:31:02 +02:00
swarm-ca.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
swarm-container-resolver.nix
fix( #3363 ): swarm containers write their own resolver file
2026-08-17 17:30:15 +02:00
swarm-controller.nix
swarm-controller: read the queue client secret from the store, drop the file
2026-09-28 19:01:05 +02:00
swarm-grafana.nix
host-modules: atomic_write_secret takes the value as an argument, not stdin
2026-09-26 21:50:03 +02:00
swarm-nats.nix
swarm: let an agent publish its own icon
2026-09-28 13:47:37 +02:00
swarm-otel.nix
host-modules: atomic_write_secret takes the value as an argument, not stdin
2026-09-26 21:50:03 +02:00
swarm-peers-removed.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm-required-services.nix
nix: run the forge on one host per swarm (deploy.forgejo.enable)
2026-09-24 23:56:07 +02:00
swarm-secret-publisher.nix
swarm-controller: read the queue client secret from the store, drop the file
2026-09-28 19:01:05 +02:00
swarm-snapshot-store.nix
deploy: move the wireguard mesh out of the namespace hives read
2026-09-07 14:24:52 +02:00
swarm-ui.nix
nix: give the gateway, resolver and bridge their own enable
2026-09-19 13:53:10 +02:00
swarm-victorialogs.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
swarm-victoriametrics.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
swarm-wireguard.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
swarm.nix
bao: serve the browser UI to admins via a loopback-only listener
2026-09-28 19:31:02 +02:00