Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/hive-agent
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas e974194e3a swarm: let an agent publish its own icon
The auth callout grants an agent that presents its own queue credential
one more subject, `$KV.agent-icons.<agent>`: its own key in the
agent-icons bucket and no other. The hive's shared agent client is
granted none of the bucket, since every agent on a hive presents it.

hive-agent writes `/etc/hyperhive/icon.svg`, the file its `GET /icon`
serves, to that key once per start, as a JetStream publish straight to
the subject (what `kv::Store::put` sends, minus the bucket lookup), so
the one subject is the whole grant. No icon deletes the key. A failed
write, including one that arrives before the bucket exists, is retried
with backoff until acked. An agent connected with the hive's shared
client publishes nothing.

swarm-controller creates the bucket as soon as its queue connection is
up, instead of on the first icon read, so an agent's write does not
wait for someone to look.

Measured against a local nats-server with a user allowed publish on
`$KV.agent-icons.atlas` only: the write to its own key is stored and
readable, a write to `$KV.agent-icons.argus` is refused (the ack times
out), the DEL marker makes the key read as absent, and a write before
the bucket exists fails with "no responders".
2026-09-28 13:47:37 +02:00
..
prompts remove the get_host_journal MCP tool and its capability 2026-09-21 19:31:45 +02:00
src swarm: let an agent publish its own icon 2026-09-28 13:47:37 +02:00
Cargo.toml swarm: let an agent publish its own icon 2026-09-28 13:47:37 +02:00
README.md docs: give turn-loop/ a README.md landing page 2026-08-03 12:55:18 +02:00

hive-agent

The in-container harness serve-loop binary — one instance per agent. Long-polls the broker inbox and drives one claude --print turn per inbox message, over the hive-claude driver. There is one role here (agent); the Surface trait + AgentSurface zero-sized type tag keep the turn loop generic and testable for future roles without a parallel copy of the loop.

When to use it

You don't call into this crate from elsewhere — it's the top-level binary systemd starts per agent container. Look here when you need to understand or change: what happens between "a message lands in the inbox" and "claude produces a reply", how login/auth is bootstrapped, how the per-agent web UI is served, or how turn/event stats get recorded. Architecture detail lives in docs/turn-loop/; this README is just the map of the module tree.

Shape

  • turn.rs — the turn-loop policy layer: renders the system prompt + MCP config, invokes hive-claude, classifies the outcome, and feeds the event/turn-stats sinks.
  • client.rs — broker client (inbox poll, ack, send) speaking the hive-sh4re wire protocol.
  • login.rs / login_session.rs — first-run and session-resume auth flow for the claude CLI.
  • mcp_config.rs — renders the per-turn --mcp-config / --allowedTools blob from tool groups + capabilities.
  • todos.rs / reminders.rs / todo_server.rs — the harness-local loose-ends v2 stores (sqlite-backed) and the in-agent socket server extra MCP daemons + hive-agent-mcp dial into for todo/reminder ops.
  • vacuum.rs — periodic sqlite vacuum sweep for the harness-local stores.
  • events.rs / turn_stats.rs / stats.rs — append-only event sink and per-turn telemetry recording (context usage, cost, tool favorites) under harness/.
  • forge_notify.rs — subscribes to forge notifications and wakes the harness on new activity.
  • prompt.rs — system-prompt renderer (persona + tool docs + environment facts).
  • web_ui/ — the per-agent dashboard (terminal pane, status, schedules) served over the built-in hive-agent web port.
  • paths.rs — canonical path resolution for state/harness dirs and the harness-local sqlite files.

Sibling: hive-agent-mcp (the MCP server this loop points claude at every turn). Both are described together in docs/turn-loop/::Harness binary shape.