Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/hive-subagent-mcp
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas c5b21403a6 hive-runtime: read the ACP provider key from bao
An opencode ACP agent got its provider API key only from the hand-placed
backendEnvironmentFile. It now also reads it from the swarm secret store
at swarm/agents/<agent>/acp-provider, field api_key, under its own
certificate, and sets it in the spawned ACP agent's environment only.
Nothing is written to disk.

Precedence: a value already in the process environment (the env file)
wins and the store is not asked. Otherwise the stored key is used when
present. With no store, nothing stored, or a failed read, the agent is
spawned without the key as before, and one line is logged without the
value.

The variable name comes from the existing per-agent option
acp.opencode.provider.apiKeyEnv, exported as HIVE_ACP_API_KEY_ENV on the
harness only for the opencode preset. Other ACP commands are unchanged.

The read lives in hive-runtime, where the ACP child is spawned, so both
hive-agent and hive-subagent-daemon use it. The subagent daemon unit
gets the key name and, when the agent has a store, the agent's store
identity (the same credentials queue-identity.nix gives the harness).

No new option or setting. Closes #4841.
2026-09-30 22:55:03 +02:00
..
src hive-runtime: read the ACP provider key from bao 2026-09-30 22:55:03 +02:00
Cargo.toml hive-subagent-mcp: run an agent's subagents on its runtime 2026-09-30 07:41:12 +02:00
README.md subagent: give each run its own signal URL, and drop the name argument 2026-09-14 22:24:51 +02:00

hive-subagent-mcp

Per-agent daemon (hive-subagent-daemon) that spawns nested headless claude sessions on request and serves the tool surface (start/continue/status/interrupt, plus a separate subagent-facing goal_reached/need_help route, one per-session URL) directly over streamable-http. No stdio bridge, no per-turn respawn — an agent's claude reconnects to the same stable URL every turn.

Independent of hive-bash-mcp — a subagent spawns a full nested claude session, a much heavier capability than a bash command, worth its own deployable/restartable unit.

Shape

One bin (hive-subagent-daemon, src/main.rs) built from the crate's own lib (src/lib.rs):

  • session.rs — the actual claude-facing logic: Claude::spawn + RunningClaude::wait/cancel_handle (not InfiniteSession::run, which has no cancel handle to reach in — see the module doc for the v1 scope this trades away), the turn-continuation loop a goal switches on, and the in-memory maps that are the only state this daemon keeps (no task files — a restart stops whatever's running; the actual claude session is the durable store, found again by name via hive_claude::SessionStore).
  • mcp.rs — the rmcp tool routers (the parent's start/continue/status/interrupt on /mcp, the subagent's goal_reached/need_help on /signal/mcp/<token>) + serve_http. Neither signal tool takes a session name: the token in the path is minted per run and resolved to a session before dispatch, so a subagent has no way to name — and therefore no way to signal — a sibling. One route with a path parameter, because the Router is built once at startup and sessions come and go for the daemon's whole life.
  • paths.rs — the in-agent todo-socket path.