| Filename | Latest commit message | Latest commit date |
|---|---|---|
The bootstrap unit writes a policy granting `secret/data/swarm/agents/*` and nothing creates that engine. A fresh OpenBao has no `secret/` — only a dev-mode one does — so `swarm-controller`'s first credential write answers `no handler for route "secret/data/swarm/agents/<agent>/matrix/<name>". route entry not found.` Measured on the live host at 21:27:27Z; #4171. `git grep` for `secrets enable`, `kv-v2`, `kv_v2` and `sys/mounts` returned zero across the whole tree. Control, so the zero means something: `auth enable` in this same file returns 2 — the same defect was already found and fixed once, for the cert auth mount, with a comment that states the principle. This is the other half of it. The mount name is now bound once and interpolated into both the policy text and the new step, because a grant and a mount that disagree is exactly the failure being fixed. Placed outside the client-CA block: the controller writes *through* this mount regardless of whether anything can log in by certificate. `module-eval` asserts that, since one indentation level decides it. Grants, measured against a real openbao 2.6.2 rather than derived: `-output-policy` asks for `sys/mounts/secret` create+update, and a token holding exactly `sys/mounts` read + `sys/mounts/<path>` create/update enabled the engine — **no `sudo`**, unlike `sys/auth/cert`. Negative control: the same token on an ungranted path got 403, so the grant is what made it work. `setup.md`'s documented policy gains those two. Also from that session, each deciding how this is written: re-enabling an existing path errors (exit 2), so this asks first like the auth mount does; `secrets list -format=json` keys look like `"secret/"`, so the `case` idiom ports over; and `kv put -mount=<p>` reports `<p>/data/...`, confirming v2 — the prefix the policy grants and the client writes. setup.md also drops a check that cannot work: it told the operator to confirm with `bao read auth/cert/…`, which 403s because the host wrapper carries no token. `systemctl status swarm-bao-controller-policy` needs no credential and names the three success lines. The first-attempt-after-rebuild race is now written down too — the store is still coming up, and the 30s retry is what lands. Refs #4171. |
||
| .. | ||
| agent-lifecycle | ||
| crates | ||
| getting-started | ||
| integrations | ||
| networking | ||
| process | ||
| scheduler | ||
| swarm | ||
| tools | ||
| trust-boundary | ||
| turn-loop | ||
| web-ui | ||
| README.md | ||
hyperhive docs
Depth reference for hyperhive — the substrate, not the pitch (that's the
top-level README / website).
Every page here stands alone; pick the one matching your task rather than
reading top to bottom. For the autogenerated NixOS options reference
(every services.hyperhive.* / hyperhive.* option, host and agent), see
the options site instead —
this tree is prose, that one's generated straight from the module
declarations.
Getting started
- Bringing a fresh hive online? →
getting-started/setup.md(first-runhivectlbootstrap). - What does the dashboard look like, and how do I use it? →
web-ui/— the operator-facing starting point; its own sub-pages (shape,dashboard,agent,css-vars,terminal-rendering) go deeper into implementation. - What tools does an agent (or the operator) have available? →
tools/—hivectl(yours) plus every agent's MCP tool surface (bash, forge, lifecycle, matrix, scheduling).
Agent lifecycle
- How do config changes flow from manager to operator to container? →
agent-lifecycle/approvals.md(two-step spawn, approval state machine,flake.lockvalidation). - What state survives destroy / purge / restart? →
agent-lifecycle/persistence.md. - Who can do what to whom — agent hierarchy and privilege? →
agent-lifecycle/agent-hierarchy.md. - How does claude get its prompt, and what tools does it have? →
turn-loop/— the loop, binary shape, turn outcomes; sub-pages:claude-invocation,config,mcp.
Trust boundary & security
- What's the operator/agent trust boundary? What's a capability? →
trust-boundary/boundary.md. - Agent trust model, prompt-injection threat model, credential
isolation? →
trust-boundary/security.md.
Accounts & integrations
- How do per-agent forge accounts work? What does
forge_notifypoll, and how does it format wake messages? →integrations/forge.md(the hive's own Forgejo);tools/forge.mdfor thehive-forgeCLI verbs agents actually call. - How does the matrix-tuwunel container work? Multiple accounts per
agent? →
integrations/matrix.md(the homeserver);tools/matrix.mdfor the MCP tool surface andhyperhive.matrixAccounts. - How do I give an agent a GitHub account (
gh+git push)? how's the PAT injected? →integrations/github.md(operator content up top; thegh/git-push + notification-poller mechanics are in a collapsed "Implementation" section at the bottom). - What's
/knowledge? How does the hive-wide knowledge repo sync, and how do I contribute a document? →integrations/knowledge.md. - What does
hivectldo? Provisioning, gateway users, container shells? →tools/hivectl.md(the curated guide);tools/hivectl-cli.mdfor the exhaustive, autogenerated flag reference.
Networking & swarms
- What nginx vhosts does the gateway serve? How does matrix
discovery work? →
networking/gateway.md. - How does DNS resolution work in agent containers? What's the
bridge network for? →
networking/network.md. - How do I connect two hives into a swarm? →
swarm/(peer hives, TLS trust). - Where do agent snapshots go? How does the swarm's
btrfs receiveendpoint authenticate a pushing hive? →networking/snapshot-store.md.
Scheduler, CI, observability
- what's the job queue, as a general idea (not hive-c0re specifics)? →
scheduler/jobq.md— operator-facing, no implementation detail. - How does the rebuild queue work? What are the concrete step kinds,
queue sources, scheduler internals? →
scheduler/coordinator.md. - How does the CI runner work? What's the autoregistration flow? →
scheduler/ci.md. - How do I export Claude Code metrics (tokens, cost, tool calls) to
Prometheus/Grafana? →
scheduler/observability.md.
Crate reference
- What does a specific Rust crate do, on its own terms? →
crates/— every workspace crate's ownREADME.md, one level up from source; the crate itself is still the source of truth, this is just a walkable mirror.
Process & conventions
- Naming, commit style, wire protocol, the
data-asyncpattern? →process/conventions.md. - Why does the nspawn flag look like that? →
process/gotchas.md(bind mounts, conf flags, other NixOS/nspawn quirks). - What does a PR review verdict actually gate? →
process/pr-review-gate.md.