hyperhive/docs
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 63fc54edc5 refactor(#3393): stop restarting authelia from swarmctl
authelia now watches the users file, so the restart is redundant -- and it
was the wrong shape twice over. It could fail: a login was refused for a
user whose record was already correct on disk, with nothing in either log
implicating the reload. And it only ever worked for this writer --
swarm-authelia-bridge writes the same file and cannot restart anything,
since running unprivileged inside the container is the whole reason it may
write it at all. A reload that depends on which process did the writing is
not a reload.

--machine/--unit and their two env vars existed solely to name a
systemctl -M target, so they go with it. That drops two required settings
from the operator surface.

The three objections previously recorded against watch are all answered
now, and are kept next to the decision rather than deleted: the key is
verified against the pinned build (validate-config accepts it and rejects
a misspelling), the watch is on the directory so a rename is observed, and
partial reads are structurally impossible because every writer of this
file goes through write_atomic.
2026-08-17 19:22:27 +02:00
..
crates docs: rename docs/components to docs/crates 2026-08-12 13:32:55 +02:00
swarm feat(#3265): feed the store from the collector, and derive the pair 2026-08-16 22:27:05 +02:00
tools refactor(#3393): stop restarting authelia from swarmctl 2026-08-17 19:22:27 +02:00
turn-loop docs(turn-loop): fix wrong HelperEvent lifecycle-event list 2026-08-15 12:45:22 +02:00
web-ui extract build-queue rollup as a shared Preact component 2026-08-16 22:08:38 +02:00
agent-hierarchy.md docs(agent-hierarchy): fix stale topology.rs path, ManagerRequest, dead reminder_scheduler.rs ref, and hardcoded forge URLs 2026-08-15 12:45:22 +02:00
approvals.md docs(approvals): fix stale internal refs verified against source 2026-08-15 12:45:22 +02:00
boundary.md docs(boundary): fix answer-question path and nonexistent AgentRequest type 2026-08-15 12:45:22 +02:00
ci.md docs(ci): fix stale nix option namespace and ensure_mirrors file path 2026-08-15 12:45:22 +02:00
conventions.md docs(conventions): fix one more stale hive-c0re.nix bare-file ref 2026-08-15 12:45:22 +02:00
coordinator.md docs(coordinator): fix stale DAG-history cap, wire request name, infra container list 2026-08-15 12:45:22 +02:00
forge.md fix(hive-forge-notify): stop embedding the issue/PR description in todos 2026-08-16 23:39:54 +02:00
gateway.md docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
github.md docs(github): move impl detail below the operator-facing sections 2026-08-02 23:54:55 +02:00
gotchas.md docs(gotchas): record how a too-narrow RestrictAddressFamilies presents 2026-08-17 17:05:18 +02:00
knowledge.md docs(knowledge): fix stale collaborator model and webhook delivery claims 2026-08-15 12:45:22 +02:00
matrix.md docs(matrix): fix stale matrix.<hive> vhost + assertion-list claims 2026-08-15 12:45:22 +02:00
network.md docs(network): fix stale forge/matrix zone claim in resolver behaviour 2026-08-15 12:45:22 +02:00
observability.md docs(#3265): observability.md still said the endpoint was required 2026-08-16 22:27:05 +02:00
persistence.md docs(persistence): fix stale facts — reminders/todos moved in-container, vacuum ownership, topology writer, matrix glob, qgroup quotas shipped 2026-08-15 12:45:22 +02:00
pr-review-gate.md docs: revise per review — no specific example, gate is per-repo config, soften auto-merge framing 2026-08-04 17:23:12 +02:00
README.md docs: rename docs/components to docs/crates 2026-08-12 13:32:55 +02:00
security.md docs(security): fix stale forge.rs path, GetAgentMeta validator, hive-priv table 2026-08-15 12:45:22 +02:00
setup.md docs: link the secrets page from setup, fix a dropped word 2026-08-14 13:22:43 +02:00
snapshot-store.md docs(snapshot-store): cross-link the state subvolume to persistence.md 2026-08-15 12:45:22 +02:00
terminal-rendering.md hive-agent: show mark_todos_done ids in the terminal, not just a count 2026-08-16 15:45:05 +02:00
web-ui.md docs(web-ui): point port-hash detail at gotchas.md instead of restating it 2026-08-15 12:45:22 +02:00

hyperhive docs

Depth reference for hyperhive — the substrate, not the pitch (that's the top-level README / website). Every page here stands alone; pick the one matching your task rather than reading top to bottom. For the auto-generated NixOS options reference (every services.hyperhive.* / hyperhive.* option, host and agent), see the options site instead — this tree is prose, that one's generated straight from the module declarations.

Getting started

  • Bringing a fresh hive online?setup.md (first-run hivectl bootstrap).
  • What does the dashboard look like, and how do I use it?web-ui/ — the operator-facing starting point; its own sub-pages (shape, dashboard, agent, css-vars) go deeper into implementation.
  • What tools does an agent (or the operator) have available?tools/hivectl (yours) plus every agent's MCP tool surface (bash, forge, lifecycle, matrix, scheduling).

Dashboard & agent UI internals

Turn loop, config, approvals

  • How does claude get its prompt, and what tools does it have?turn-loop/ — the loop, binary shape, turn outcomes; sub-pages: claude-invocation, config, mcp.
  • How do config changes flow from manager to operator to container?approvals.md (two-step spawn, approval state machine, flake.lock validation).
  • What state survives destroy / purge / restart?persistence.md.

Trust boundary & security

  • What's the operator/agent trust boundary? What's a capability?boundary.md.
  • Agent trust model, prompt-injection threat model, credential isolation?security.md.
  • Who can do what to whom — agent hierarchy and privilege?agent-hierarchy.md.

Accounts & integrations

  • How do per-agent forge accounts work? What does forge_notify poll, and how does it format wake messages?forge.md (the hive's own Forgejo); tools/forge.md for the hive-forge CLI verbs agents actually call.
  • How does the matrix-tuwunel container work? Multiple accounts per agent?matrix.md (the homeserver); tools/matrix.md for the MCP tool surface and hyperhive.matrixAccounts.
  • How do I give an agent a GitHub account (gh + git push)? How is the PAT injected?github.md.
  • What does hivectl do? Provisioning, gateway users, container shells?tools/hivectl.md (the curated guide); tools/hivectl-cli.md for the exhaustive, auto-generated flag reference.

Networking & swarms

  • What nginx vhosts does the gateway serve? How does matrix discovery work?gateway.md.
  • How does DNS resolution work in agent containers? What's the bridge network for?network.md.
  • How do I connect two hives into a swarm?swarm/ (peer hives, TLS trust).
  • Where do agent snapshots go? How does the swarm's btrfs receive endpoint authenticate a pushing hive?snapshot-store.md.

Scheduler, CI, observability

  • How does the rebuild queue work? What are queue kinds and sources?coordinator.md.
  • How does the CI runner work? What's the auto-registration flow?ci.md.
  • How do I export Claude Code metrics (tokens, cost, tool calls) to Prometheus/Grafana?observability.md.

Crate reference

  • What does a specific Rust crate do, on its own terms?crates/ — every workspace crate's own README.md, one level up from source (hyperhive#3051); the crate itself is still the source of truth, this is just a walkable mirror.

Process & conventions

  • Naming, commit style, wire protocol, the data-async pattern?conventions.md.
  • Why does the nspawn flag look like that?gotchas.md (bind mounts, conf flags, other NixOS/nspawn quirks).
  • What is /knowledge? How does the hive-wide knowledge repo sync, and how do I contribute a document?knowledge.md.