The auth callout grants an agent that presents its own queue credential one more subject, `$KV.agent-icons.<agent>`: its own key in the agent-icons bucket and no other. The hive's shared agent client is granted none of the bucket, since every agent on a hive presents it. hive-agent writes `/etc/hyperhive/icon.svg`, the file its `GET /icon` serves, to that key once per start, as a JetStream publish straight to the subject (what `kv::Store::put` sends, minus the bucket lookup), so the one subject is the whole grant. No icon deletes the key. A failed write, including one that arrives before the bucket exists, is retried with backoff until acked. An agent connected with the hive's shared client publishes nothing. swarm-controller creates the bucket as soon as its queue connection is up, instead of on the first icon read, so an agent's write does not wait for someone to look. Measured against a local nats-server with a user allowed publish on `$KV.agent-icons.atlas` only: the write to its own key is stored and readable, a write to `$KV.agent-icons.argus` is refused (the ack times out), the DEL marker makes the key read as absent, and a write before the bucket exists fails with "no responders".
55 lines
1.7 KiB
TOML
55 lines
1.7 KiB
TOML
[package]
|
|
name = "hive-agent"
|
|
edition.workspace = true
|
|
version.workspace = true
|
|
readme = "README.md"
|
|
|
|
[lints]
|
|
workspace = true
|
|
|
|
[dependencies]
|
|
anyhow.workspace = true
|
|
# Named directly for the client type the publishers hold, and for `jetstream`,
|
|
# which the icon publisher's acked write needs. The connect and the credential
|
|
# handling live in `swarm-queue-client` below.
|
|
async-nats = { workspace = true, features = ["jetstream"] }
|
|
axum.workspace = true
|
|
chrono.workspace = true
|
|
reqwest.workspace = true
|
|
hyper.workspace = true
|
|
hyper-util.workspace = true
|
|
http-body-util.workspace = true
|
|
futures-util = "0.3"
|
|
clap.workspace = true
|
|
hive-claude.workspace = true
|
|
hive-agent-sock.workspace = true
|
|
hive-core-agent-sock.workspace = true
|
|
hive-log.workspace = true
|
|
hive-sh4re.workspace = true
|
|
hive-sock-client.workspace = true
|
|
libc.workspace = true
|
|
opentelemetry.workspace = true
|
|
opentelemetry_sdk.workspace = true
|
|
opentelemetry-otlp.workspace = true
|
|
rmcp.workspace = true
|
|
rusqlite.workspace = true
|
|
schemars.workspace = true
|
|
serde.workspace = true
|
|
serde_json.workspace = true
|
|
# Bare: `kv`/`notices` name buckets and streams this harness opens neither end
|
|
# of. The terminal publisher is a plain core-subject publish, so it needs the
|
|
# connect and the payload limit and nothing from JetStream.
|
|
swarm-queue-client.workspace = true
|
|
tokio.workspace = true
|
|
tokio-stream.workspace = true
|
|
tower-http.workspace = true
|
|
tracing.workspace = true
|
|
|
|
[dev-dependencies]
|
|
tempfile = "3"
|
|
|
|
# Single harness serve-loop binary: `hive-agent` (from `src/main.rs`).
|
|
# The sibling MCP server is its own bin crate now (`hive-agent-mcp`).
|
|
# Privilege boundary is enforced server-side at the socket (tool
|
|
# groups / manager surface).
|
|
# See `docs/turn-loop/README.md::Harness binary shape`.
|