hyperhive/docs
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 1a3f82a459 nix(gateway): self-signed TLS as the implicit default, deprecate the toggle
Make self-signed TLS the gateway's default whenever no external TLS source
is configured, and deprecate the explicit selfSignedTls toggle. Self-signed
is now derived as `tls.certDir == null && !tls.acme.enable`, so an operator
selects a TLS mode by setting tls.certDir or tls.acme — or neither, for the
self-signed default. There is no http-only mode: matrix discovery hardcodes
https, so the gateway always terminates TLS.

The selfSignedTls option is kept as a deprecated no-op (warns when set to
false) so existing configs still eval. The two selfSignedTls mutual-
exclusion assertions and the HSTS-requires-TLS assertion are dropped — they
are impossible or vacuous now that self-signed is the floor. The hive-tls
module and the forge ROOT_URL scheme consume the derived value: the gateway
always terminates TLS, so behind the gateway the forge is always advertised
over https.

Updates docs/gateway.md (TLS-modes table, self-signed section, the removed
http-only section, firewall + discovery notes). Eval-proven: default →
self-signed (hive CA active, https ROOT_URL); tls.certDir → CA inactive;
selfSignedTls=false → deprecation warning fires.
2026-06-17 21:14:05 +02:00
..
tools list: paging via --page instead of --all (token-bounded per call, per review) 2026-06-17 13:49:45 +02:00
web-ui docs(web-ui): update P3RM1SS10NS section for the save-all button 2026-06-17 19:14:59 +02:00
agent-hierarchy.md refactor: remove hyperhive.role option — there is only one role: agent 2026-06-04 14:31:44 +02:00
approvals.md docs(#1014): update stale root→ruth references in conventions, approvals, agent-hierarchy 2026-06-02 22:48:10 +02:00
boundary.md docs: move privsep socket-activation + child-state rw rationale out of code comments 2026-06-08 21:58:12 +02:00
ci.md docs(ci): document jobTimeout, fix forge.ci option path 2026-06-15 11:37:50 +02:00
conventions.md fix(#1548): make set_status always-on regardless of tool groups 2026-06-09 00:28:40 +02:00
coordinator.md docs(coordinator): document agentCpuQuota, agentMemoryMax, preBuildAgentTemplates 2026-06-05 18:27:05 +02:00
forge.md fix(#1637): don't label later activity (bodiless reviews) as new PR 2026-06-13 12:20:21 +02:00
gateway.md nix(gateway): self-signed TLS as the implicit default, deprecate the toggle 2026-06-17 21:14:05 +02:00
gotchas.md docs: note that linking workspace binaries locally needs nix develop (libsqlite3) 2026-06-05 21:30:57 +02:00
knowledge.md docs(knowledge): document the hive-forge AGit no-fork contribution flow 2026-06-05 20:54:25 +02:00
matrix.md feat(#551): gate server-side e2ee behind opt-in matrix.allowEncryption (default off) 2026-06-10 19:12:36 +02:00
network.md docs(network): document container-side route + resolver wiring for isolation 2026-06-10 21:49:01 +02:00
persistence.md docs: move privsep socket-activation + child-state rw rationale out of code comments 2026-06-08 21:58:12 +02:00
security.md fix: update PrivRequest table to match actual hive-sh4re::priv_proto variants 2026-06-05 18:40:44 +02:00
swarm.md docs: clarify certFingerprint does not govern matrix federation tls 2026-06-06 00:21:52 +02:00
terminal-rendering.md docs(web-ui): document turn start/end times + duration on the agent terminal 2026-06-10 15:38:04 +02:00
turn-loop.md docs: drop stale two-loop/two-binary framings (single hive serve loop) 2026-06-10 20:01:52 +02:00
web-ui.md docs(web-ui): sync dashboard docs after the SYST3M → C0R3 page move 2026-06-10 21:49:12 +02:00