| Filename | Latest commit message | Latest commit date |
|---|---|---|
An opencode ACP agent got its provider API key only from the hand-placed backendEnvironmentFile. It now also reads it from the swarm secret store at swarm/agents/<agent>/acp-provider, field api_key, under its own certificate, and sets it in the spawned ACP agent's environment only. Nothing is written to disk. Precedence: a value already in the process environment (the env file) wins and the store is not asked. Otherwise the stored key is used when present. With no store, nothing stored, or a failed read, the agent is spawned without the key as before, and one line is logged without the value. The variable name comes from the existing per-agent option acp.opencode.provider.apiKeyEnv, exported as HIVE_ACP_API_KEY_ENV on the harness only for the opencode preset. Other ACP commands are unchanged. The read lives in hive-runtime, where the ACP child is spawned, so both hive-agent and hive-subagent-daemon use it. The subagent daemon unit gets the key name and, when the agent has a store, the agent's store identity (the same credentials queue-identity.nix gives the harness). No new option or setting. Closes #4841. |
||
| .. | ||
| src | ||
| Cargo.toml | ||
| README.md | ||
hive-subagent-mcp
Per-agent daemon (hive-subagent-daemon) that spawns nested headless
claude sessions on request and serves the tool surface
(start/continue/status/interrupt, plus a separate
subagent-facing goal_reached/need_help route, one per-session URL)
directly over streamable-http. No stdio bridge, no per-turn respawn — an
agent's claude reconnects to the same stable URL every turn.
Independent of hive-bash-mcp — a subagent spawns a full nested
claude session, a much heavier capability than a bash command, worth
its own deployable/restartable unit.
Shape
One bin (hive-subagent-daemon, src/main.rs) built from the crate's
own lib (src/lib.rs):
session.rs— the actual claude-facing logic:Claude::spawn+RunningClaude::wait/cancel_handle(notInfiniteSession::run, which has no cancel handle to reach in — see the module doc for the v1 scope this trades away), the turn-continuation loop agoalswitches on, and the in-memory maps that are the only state this daemon keeps (no task files — a restart stops whatever's running; the actual claude session is the durable store, found again by name viahive_claude::SessionStore).mcp.rs— thermcptool routers (the parent'sstart/continue/status/interrupton/mcp, the subagent'sgoal_reached/need_helpon/signal/mcp/<token>) +serve_http. Neither signal tool takes a session name: the token in the path is minted per run and resolved to a session before dispatch, so a subagent has no way to name — and therefore no way to signal — a sibling. One route with a path parameter, because theRouteris built once at startup and sessions come and go for the daemon's whole life.paths.rs— the in-agent todo-socket path.