hyperhive/docs
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 74a90fd7d6 nix(tls): host hive-CA + gateway leaf for self-signed mode
Replace the gateway's bare in-container self-signed leaf with a leaf
signed by a host-held hive CA. A bare self-signed leaf is its own trust
anchor, so every regeneration is a fresh anchor every consumer would have
to re-trust, and a runtime-generated in-container leaf cannot be wired
into an agent's build-time trust store at all. A stable CA fixes both: a
single anchor that agents and federation peers trust once, surviving leaf
rotation.

New hive-tls module: a host oneshot generates a long-lived CA (default
~20y) under services.hyperhive.tls.stateDir and signs a gateway leaf
(default ~10y, SAN covering the bare domain, forge., matrix. and the
wildcard). It is ordered before the gateway container so the leaf exists
when nginx starts. Active only when the gateway uses self-signed TLS
(default) and a domain is set; inert under operator-cert or ACME modes.

Gateway: bind-mount the host CA dir read-only at /run/hive-ca; the
existing in-container cert unit now imports the host leaf into nginx's
state dir (copy as root, key left root:nginx 0640 for the pre-start
config test) instead of generating one. Cert/key paths nginx serves are
unchanged.

Foundational step toward agent + federation trust of self-signed hives;
no behaviour change for agents yet (they still reach the forge over plain
http on port 80). Eval-proven across self-signed, certDir and the inert
default paths.
2026-06-17 19:04:52 +02:00
..
tools list: paging via --page instead of --all (token-bounded per call, per review) 2026-06-17 13:49:45 +02:00
web-ui feat(dashboard): batch POST /api/permissions for save-all perms (#1719) 2026-06-17 18:21:56 +02:00
agent-hierarchy.md refactor: remove hyperhive.role option — there is only one role: agent 2026-06-04 14:31:44 +02:00
approvals.md docs(#1014): update stale root→ruth references in conventions, approvals, agent-hierarchy 2026-06-02 22:48:10 +02:00
boundary.md docs: move privsep socket-activation + child-state rw rationale out of code comments 2026-06-08 21:58:12 +02:00
ci.md docs(ci): document jobTimeout, fix forge.ci option path 2026-06-15 11:37:50 +02:00
conventions.md fix(#1548): make set_status always-on regardless of tool groups 2026-06-09 00:28:40 +02:00
coordinator.md docs(coordinator): document agentCpuQuota, agentMemoryMax, preBuildAgentTemplates 2026-06-05 18:27:05 +02:00
forge.md fix(#1637): don't label later activity (bodiless reviews) as new PR 2026-06-13 12:20:21 +02:00
gateway.md nix(tls): host hive-CA + gateway leaf for self-signed mode 2026-06-17 19:04:52 +02:00
gotchas.md docs: note that linking workspace binaries locally needs nix develop (libsqlite3) 2026-06-05 21:30:57 +02:00
knowledge.md docs(knowledge): document the hive-forge AGit no-fork contribution flow 2026-06-05 20:54:25 +02:00
matrix.md feat(#551): gate server-side e2ee behind opt-in matrix.allowEncryption (default off) 2026-06-10 19:12:36 +02:00
network.md docs(network): document container-side route + resolver wiring for isolation 2026-06-10 21:49:01 +02:00
persistence.md docs: move privsep socket-activation + child-state rw rationale out of code comments 2026-06-08 21:58:12 +02:00
security.md fix: update PrivRequest table to match actual hive-sh4re::priv_proto variants 2026-06-05 18:40:44 +02:00
swarm.md docs: clarify certFingerprint does not govern matrix federation tls 2026-06-06 00:21:52 +02:00
terminal-rendering.md docs(web-ui): document turn start/end times + duration on the agent terminal 2026-06-10 15:38:04 +02:00
turn-loop.md docs: drop stale two-loop/two-binary framings (single hive serve loop) 2026-06-10 20:01:52 +02:00
web-ui.md docs(web-ui): sync dashboard docs after the SYST3M → C0R3 page move 2026-06-10 21:49:12 +02:00