Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/swarm-controller/src
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas e974194e3a swarm: let an agent publish its own icon
The auth callout grants an agent that presents its own queue credential
one more subject, `$KV.agent-icons.<agent>`: its own key in the
agent-icons bucket and no other. The hive's shared agent client is
granted none of the bucket, since every agent on a hive presents it.

hive-agent writes `/etc/hyperhive/icon.svg`, the file its `GET /icon`
serves, to that key once per start, as a JetStream publish straight to
the subject (what `kv::Store::put` sends, minus the bucket lookup), so
the one subject is the whole grant. No icon deletes the key. A failed
write, including one that arrives before the bucket exists, is retried
with backoff until acked. An agent connected with the hive's shared
client publishes nothing.

swarm-controller creates the bucket as soon as its queue connection is
up, instead of on the first icon read, so an agent's write does not
wait for someone to look.

Measured against a local nats-server with a user allowed publish on
`$KV.agent-icons.atlas` only: the write to its own key is stored and
readable, a write to `$KV.agent-icons.argus` is refused (the ack times
out), the DEL marker makes the key read as absent, and a write before
the bucket exists fails with "no responders".
2026-09-28 13:47:37 +02:00
..
forge swarm-controller: own the swarm-wide forge objects; hive-c0re stops creating them 2026-09-25 08:36:05 +02:00
matrix_account swarm-controller: mint each agent's matrix account with the swarm's token 2026-09-25 08:31:01 +02:00
agent_icon.rs swarm: let an agent publish its own icon 2026-09-28 13:47:37 +02:00
agent_identity.rs swarm-queue-client: one agent-token spelling, and no hive in AgentCredential 2026-09-28 08:24:52 +02:00
agent_state_stream.rs swarm-controller: relay an agent's hive-free subjects beside the old ones 2026-09-28 08:24:52 +02:00
agent_status.rs swarm-ui: add agent start/stop, backed by the wanted-state route 2026-09-02 19:57:04 +02:00
auth.rs hive-sock-client, web proxy, HTTP clients: bound connect and response waits 2026-09-27 03:46:53 +02:00
config_pr.rs swarm-controller: fix stale route reference in snapshot's doc comment 2026-08-19 22:27:12 +02:00
forge.rs swarm-controller: own the swarm-wide forge objects; hive-c0re stops creating them 2026-09-25 08:36:05 +02:00
issue_report.rs swarm-controller: answer 404, not 503, for an issue-report on a nonexistent repo 2026-09-24 16:38:47 +02:00
main.rs swarm: let an agent publish its own icon 2026-09-28 13:47:37 +02:00
matrix_account.rs swarm: serve an agent's icon at swarm scope 2026-09-28 13:47:37 +02:00
otel_http_client.rs swarm-queue-client: request the bearer-authz scope when minting an agent token 2026-09-17 09:51:44 +02:00
read_policy.rs swarm: say the read policy names the hive it is written for 2026-09-12 11:41:01 +02:00
status.rs swarm-controller: make status::render/row pub(crate) so agent_status.rs's doc links resolve 2026-09-02 10:20:29 +02:00
store.rs fix doc-comment pointers broken by the module-eval split 2026-09-20 04:31:08 +02:00
term_stream.rs swarm-controller: relay an agent's hive-free subjects beside the old ones 2026-09-28 08:24:52 +02:00
vcs_metrics.rs docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
wanted.rs swarm-controller: trim oversized comments, drop a trivial wrapper fn 2026-09-18 22:59:29 +02:00
webhook.rs swarm-controller: own the swarm-wide forge objects; hive-c0re stops creating them 2026-09-25 08:36:05 +02:00