atlas
170fd817ea
fix(hivectl): ask the daemon whether an agent exists
...
The agents root is 0700 and owned by the daemon's user, so hivectl's
client-side existence guard hit EACCES on traversal for anyone not root.
It reported that as "this command needs root; re-run with sudo", which
turned three verbs' pre-flight check into a permission error about the
wrong thing: `choom`, `subvol upgrade` and `subvol snapshot create` all
failed at the guard rather than at whatever they actually needed.
The daemon runs as the owning user and already answers this question for
its own provisioning paths, so expose it on the host socket as
`AgentExists` and have hivectl ask. Operators reach that socket through
the `hive-admin` group, so the guard now works without sudo.
`choom` still needs root for `machinectl shell` — we ship no polkit rule
granting those actions — so it now checks the effective uid and says so
directly instead of failing later inside systemd's authorisation.
2026-07-27 09:34:43 +02:00
..
tools
fix(hivectl): ask the daemon whether an agent exists
2026-07-27 09:34:43 +02:00
turn-loop
feat(agent): ship Anthropic's skill-creator plugin by default
2026-07-26 20:28:51 +02:00
web-ui
job_queue: retire the now-off-wire step sub-step label
2026-07-26 15:24:35 +02:00
agent-hierarchy.md
refactor(hive-agent): split the forge notification poller into its own crate
2026-07-26 21:30:29 +02:00
approvals.md
job_queue: grow the rebuild subgraph from DeployApply ( #2664 )
2026-07-26 02:28:03 +02:00
boundary.md
feat( #2641 ): sudoless hivectl via a hive-admin group on the host socket
2026-07-22 22:50:27 +02:00
ci.md
docs( #2415 ): update docs/ci.md for c0re-owned runner registration
2026-07-16 15:30:34 +02:00
conventions.md
docs( #2552 ): never add #[allow(clippy::...)] — fix lints instead
2026-07-20 19:38:56 +02:00
coordinator.md
job_queue: add NodeKind::Reparent (topology moves as a queue node, #2719 )
2026-07-26 19:47:36 +02:00
forge.md
refactor(hive-agent): split the forge notification poller into its own crate
2026-07-26 21:30:29 +02:00
gateway.md
route gateway htpasswd management through a daemon wire command ( #2504 )
2026-07-15 23:23:47 +02:00
github.md
fix( #1970 ): bake token path into gh/git wrappers — env var didn't reach claude's bash-tool context
2026-07-11 14:12:25 +02:00
gotchas.md
docs: reflect the new nix layout and removed options
2026-07-13 22:23:20 +02:00
knowledge.md
docs(security): ci netns, knowledge .git tmpfs, matrix id/secret split
2026-07-10 19:17:17 +02:00
matrix.md
refactor: nix/host-modules + nix/agent-modules layout, update doc paths
2026-07-13 22:05:49 +02:00
network.md
fix(gateway): resync the gateway's resolv.conf when the host's changes
2026-07-26 18:01:34 +02:00
observability.md
feat( #2007 ): export per-agent container cpu/mem/disk via otel
2026-07-15 22:51:31 +02:00
persistence.md
refactor(hive-agent): split the forge notification poller into its own crate
2026-07-26 21:30:29 +02:00
security.md
refactor: nix/host-modules + nix/agent-modules layout, update doc paths
2026-07-13 22:05:49 +02:00
setup.md
refactor( #2416 ): remove the non-pr config-change flow (request_apply_commit / applycommit)
2026-07-15 21:03:52 +02:00
swarm.md
feat( #1997 ): add prettier markdown formatter to treefmt
2026-07-02 23:33:11 +02:00
terminal-rendering.md
refactor( #2416 ): remove the non-pr config-change flow (request_apply_commit / applycommit)
2026-07-15 21:03:52 +02:00
turn-loop.md
refactor(hive-agent): split the forge notification poller into its own crate
2026-07-26 21:30:29 +02:00
web-ui.md
feat: rename matrix-accounts page to credentials, add github PAT tab
2026-07-11 12:40:13 +02:00