atlas
7f9e65e923
swarm-controller: hand the daemon the authority hives are issued from
...
Creating a hive's cert-auth role means writing the authority into the role
by value -- the store matches a presented certificate against the role's own
copy -- and nothing gave this daemon that file.
Named separately from deploy.bao.clientCaFile rather than read off it: that
option is the store's, saying which readers the store trusts on the host
that runs it, while a controller runs anywhere. The glue module supplies it
where the two are co-located, which is the same split baoClientCertFile
already makes against the hive reader's leaf.
Gated on the identity as well as the CA. Without a leaf there is nothing to
write a role with, so the file would reach a daemon that cannot act on it.
The module-eval arm needed a fixture of its own: a deployment that
self-signs both ends points clientCaFile and serverCaFile at one file, so on
the existing fixture the two authorities are the same string and wiring
either into the other's slot passes. controllerTwoCas is where they differ.
2026-09-10 00:25:07 +02:00
..
hive-c0re
hive-c0re: grant hive-admin group a polkit rule for choom
2026-09-07 23:27:15 +02:00
hive-forge
forge: move the forgejo package to deploy — slice 10 complete
2026-09-07 20:46:38 +02:00
hive-gateway
docs: matrix gateway vhost defaults to chat.<swarm-domain>, not matrix.<domain>
2026-09-07 16:53:22 +02:00
lib
swarm: extract the name guards, so the module just says what is forbidden
2026-08-31 18:50:15 +02:00
swarm-grafana /dashboards
grafana: show which sources are shipping, not just that the store is up
2026-09-08 00:43:23 +02:00
default.nix
bao: mint the controller's leaf, and point the controller at it
2026-09-07 22:24:42 +02:00
deploy.nix
forge: move the forgejo package to deploy — slice 10 complete
2026-09-07 20:46:38 +02:00
glue-bao-tls.nix
bao: mint the controller's leaf, and point the controller at it
2026-09-07 22:24:42 +02:00
glue-controller-bao-identity.nix
swarm-controller: hand the daemon the authority hives are issued from
2026-09-10 00:25:07 +02:00
glue-matrix-bao-token.nix
deploy: split the homeserver's host decisions out of swarm.matrix
2026-09-07 14:24:52 +02:00
hive-ci.nix
deploy: split the forge's host decisions out of swarm.forge
2026-09-07 14:24:52 +02:00
hive-matrix.nix
swarm: move the matrix packages to deploy, where their enable already lives
2026-09-07 20:46:37 +02:00
hive-network.nix
docs: restructure into topic subdirectories, collapse duplicated index
2026-09-02 01:55:37 +02:00
hive-priv.nix
docs: restructure into topic subdirectories, collapse duplicated index
2026-09-02 01:55:37 +02:00
hive-tls.nix
docs: restructure into topic subdirectories, collapse duplicated index
2026-09-02 01:55:37 +02:00
hyperhive.nix
docs: restructure into topic subdirectories, collapse duplicated index
2026-09-02 01:55:37 +02:00
local-defaults.nix
bao: write the swarm controller's policy from inside the store
2026-09-07 18:43:09 +02:00
otel.nix
deploy: move authelia's three host paths out of swarm.authelia
2026-09-07 15:44:07 +02:00
stylix-theme.nix
swarm-ui: apply the operator's stylix theme, same as the dashboard already does
2026-08-24 14:28:25 +02:00
swarm-authelia.nix
swarm: move both authelia packages to deploy
2026-09-07 20:46:38 +02:00
swarm-bao.nix
swarm-bao: let the controller write agent credentials, and gate that it can
2026-09-09 01:19:57 +02:00
swarm-ca.nix
swarm-ca: state the store-is-world-readable rule once, not three times
2026-09-02 09:03:35 +02:00
swarm-container-resolver.nix
fix( #3363 ): swarm containers write their own resolver file
2026-08-17 17:30:15 +02:00
swarm-controller.nix
swarm-controller: hand the daemon the authority hives are issued from
2026-09-10 00:25:07 +02:00
swarm-grafana.nix
grafana: show which sources are shipping, not just that the store is up
2026-09-08 00:43:23 +02:00
swarm-nats.nix
swarm: move the queue's responder package to deploy
2026-09-07 20:46:38 +02:00
swarm-otel.nix
nix: split statusPublish and the otel secret into deploy.*
2026-09-07 16:54:23 +02:00
swarm-peers-removed.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm-required-services.nix
deploy: rename enableAllLocalDefaults to deploy.singleHostSwarm
2026-08-30 20:12:16 +02:00
swarm-snapshot-store.nix
deploy: move the wireguard mesh out of the namespace hives read
2026-09-07 14:24:52 +02:00
swarm-ui.nix
swarm: move the controller's two packages to deploy
2026-09-07 20:46:38 +02:00
swarm-victorialogs.nix
swarm: move both metric stores' package to deploy, and cover their shims
2026-09-07 20:46:38 +02:00
swarm-victoriametrics.nix
swarm: move both metric stores' package to deploy, and cover their shims
2026-09-07 20:46:38 +02:00
swarm-wireguard.nix
deploy: move the wireguard mesh out of the namespace hives read
2026-09-07 14:24:52 +02:00
swarm.nix
nix: split statusPublish and the otel secret into deploy.*
2026-09-07 16:54:23 +02:00