mara asked, and the file had already stopped being one thing: after the gate moved off c0re.enable, swarm.nix held two concerns with different audiences and different gates. swarm.nix now declares WHO the peers are — data hive-c0re serialises into HYPERHIVE_PEERS and the dashboard renders. Declaration only, no config block. swarm-wireguard.nix owns the mesh: assertions, the wg-hive interface, the firewall port. That is plain host networking, and a machine which runs no hive at all — the snapshot store — still needs it. Under the old layout a reader could not tell which half of swarm.nix applied to a non-hive host. The two stay coupled by data, not by structure: the per-peer wireguard* fields stay on the peer submodule, because that is where a peer is described, and the mesh module reads them. No behaviour change — same options, same gate, same rendered config.
28 lines
961 B
Nix
28 lines
961 B
Nix
# The full hyperhive host stack, pulled together in one place — this
|
|
# is what the flake exports as `nixosModules.default` (wrapped with
|
|
# the package/source wiring; see flake.nix). One import covers
|
|
# everything; `services.hyperhive.enable = true` turns the stack on.
|
|
#
|
|
# The forge is mandatory — hive-c0re mirrors every agent's applied
|
|
# config repo into it and it's the canonical store for the meta flake
|
|
# + `internal/*` repos, so there's no enable toggle; it deploys with
|
|
# hyperhive itself. hive-matrix is opt-in (off by default). All
|
|
# subsystems rely on `services.hyperhive.domain`, which is required
|
|
# (asserted in hive-network.nix) whenever hyperhive is enabled.
|
|
{
|
|
imports = [
|
|
./hyperhive.nix
|
|
./hive-c0re
|
|
./hive-ci.nix
|
|
./hive-forge
|
|
./hive-gateway
|
|
./hive-matrix.nix
|
|
./hive-network.nix
|
|
./hive-priv.nix
|
|
./hive-snapshot-store.nix
|
|
./hive-tls.nix
|
|
./otel.nix
|
|
./swarm-wireguard.nix
|
|
./swarm.nix
|
|
];
|
|
}
|