| Filename | Latest commit message | Latest commit date |
|---|---|---|
hive-c0re's container-resource exporter already targets this hive's own collector (environment.nix derives the bridge address), so the upstream header it was loaded with has nowhere to be presented: that hop is unauthenticated for every producer on the host, and the credential belongs to the swarm tier, which is the one that leaves the swarm. Drop the LoadCredential entry and the auth_headers() reader with it. The option itself stays -- swarm-otel.nix is its real consumer, via EnvironmentFile on the collector unit. Also corrects three descriptions that this makes false, or that were already false: the module doc claimed to reuse the config "Claude Code's in-container SDK export uses", which stopped being true when agents moved off that path; the nix comment claimed the secret is "the same one the agent containers get, forwarded via nspawn --load-credential", which lost its last producer earlier; and docs/observability.md described an Authorization header on a hop that will no longer send one. The headersCredential option's own docs already said it reaches "neither an agent container nor a hive's own collector" -- this makes that true rather than aspirational. |
||
| .. | ||
| src | ||
| Cargo.toml | ||
| README.md | ||
hive-c0re
The unprivileged host daemon (runs as hive-core). Owns the sqlite
broker, the approval/question/schedule queues, the generic job-DAG
queue, container lifecycle, gateway/forge/matrix provisioning,
per-container stats, and the axum operator dashboard. Largest crate in
the workspace — bin-only, no separate lib.
When to use it
Host-level, cross-container orchestration: spawning/rebuilding/
destroying agent containers, the approval flow, dashboard-visible
state, provisioning per-agent forge/matrix/gateway accounts. Agent-side
behavior (turn loop, MCP tools) lives in hive-agent/hive-agent-mcp
instead — this daemon only talks to agents over the socket wire types
in hive-sh4re.
Shape
Cohesive clusters live in directory submodules, each re-exported at
the crate root (crate::broker::… keeps resolving regardless of which
subdirectory a module actually lives in). One line each — read the
module's own //! doc-comment for real detail, don't expect this file
to track it:
dashboard/— the operator dashboard (containers, approvals, schedules, questions, logs, topology).job_queue/— the job-DAG queue + desired-state reconciliation (docs/coordinator.md).lifecycle/—nixos-containerlifecycle + per-agent config flake generation.stores/— sqlite-backed stores (broker, queues, audit, power).workers/— background sweeps (crash watch, scheduled prompts, auto-update, knowledge sync).agent_config/— per-agent registries (tool groups, capabilities, resource limits, topology).stats/— dashboard metrics aggregation + OTEL export.socket_server/— the unix-socket request server shared by per-agent + manager sockets.forge/— optional Forgejo wiring (docs/forge.md).coordinator.rs— top-level wiring forserve.meta.rs,migrate.rs— the meta flake + schema/state migrations.matrix.rs,gateway_nginx.rs,webhook_secret.rs,priv_client.rs— matrix provisioning, gateway vhosts, webhook secrets, and thehive-privclient respectively.
See the top-level CLAUDE.md/docs/ index for the full reading-path
map.