hyperhive/nix/host-modules
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 0d88ca5e7f swarm-controller: accept an agent's external matrix account and put it in the store
The swarm UI had nowhere to POST an external matrix account to: this daemon
had no matrix-account code at all and no `swarm-secret-client` dependency, so
the last leg of #3726 — a credential reaching an agent — had no entry point.

`PUT /api/hives/{hive}/agents/{agent}/matrix-accounts/{account}` writes the
credential to the store under the agent's own path and publishes a
`CredentialNotice` on that hive's credential subject. All three path names are
load-bearing: agent + account locate the secret, hive routes the notice. The
account is a path segment rather than a body field so that splitting the 1:1
account-to-agent mapping later is a new route, not a changed payload.

Store first, notify second, and the order cannot be swapped: a notice that
overtakes its own write reaches a hive that reads nothing, and the hive
deliberately does not retry. The publish is followed by a flush for the reason
`publish_deploy` flushes — `publish` hands the message to the connection's
write buffer and returns, so the response could otherwise outrun the notice it
reports as sent.

The store client is built per request rather than held in `AppState`, matching
what the hive side does inside `deliver`: a login that expires is not worth
caching for a route this cold.

`swarm_hive` is `declaration_target`'s two name checks, extracted so this
handler makes them identically rather than in a second copy free to drift.
`declaration_target` still tests the writer first, so a deployment with no
queue answers 503 whatever the caller spelled.

## The nix half

#4081 minted the controller's leaf and gave it `baoClientCertFile` /
`baoClientKeyFile`, deliberately stopping there — the leaf is minted whether or
not a controller runs on that host. Nothing consumed those options, so the
identity never reached the process. Measured before writing: `git grep
baoClientCertFile` returned 5 sites and zero consumers, against a control
(`tokenEndpoint`, 4 hits in the same file) proving the search can see
consumption where it exists.

The unit now gets `BAO_ADDR` / `BAO_CLIENT_CERT` / `BAO_CLIENT_KEY` /
`BAO_CACERT` and the matching `LoadCredential` entries, following
`hive-c0re/environment.nix`'s `%d` credential shape.

The gate is `deploy.swarm-controller.baoClientCertFile`, NOT
`deploy.bao.clientCertFile`. The latter is the hive reader's identity and its
policy scopes a hive's own secrets; wiring it here would evaluate, deploy, and
fail only when the daemon tried to write an agent's credential.

Two `module-eval` arms cover exactly that. The presence arm asserts the
`LoadCredential` *source path* (`…:/var/lib/swarm-bao-pki/controller.pem`) and
not just the `%d` name, because a `%d`-only assertion passes while the daemon
holds the wrong policy. The absence arm (`controllerNoStore`) is what makes the
presence arm mean anything.

`RestrictAddressFamilies` already covers the store client; its own comment asks
for the family to be added with the client, and AF_INET/AF_INET6 are present.

Contributes to #3726
2026-09-08 15:53:50 +02:00
..
hive-c0re hive-c0re: grant hive-admin group a polkit rule for choom 2026-09-07 23:27:15 +02:00
hive-forge forge: move the forgejo package to deploy — slice 10 complete 2026-09-07 20:46:38 +02:00
hive-gateway docs: matrix gateway vhost defaults to chat.<swarm-domain>, not matrix.<domain> 2026-09-07 16:53:22 +02:00
lib swarm: extract the name guards, so the module just says what is forbidden 2026-08-31 18:50:15 +02:00
swarm-grafana/dashboards grafana: show which sources are shipping, not just that the store is up 2026-09-08 00:43:23 +02:00
default.nix bao: mint the controller's leaf, and point the controller at it 2026-09-07 22:24:42 +02:00
deploy.nix forge: move the forgejo package to deploy — slice 10 complete 2026-09-07 20:46:38 +02:00
glue-bao-tls.nix bao: mint the controller's leaf, and point the controller at it 2026-09-07 22:24:42 +02:00
glue-controller-bao-identity.nix bao: mint the controller's leaf, and point the controller at it 2026-09-07 22:24:42 +02:00
glue-matrix-bao-token.nix deploy: split the homeserver's host decisions out of swarm.matrix 2026-09-07 14:24:52 +02:00
hive-ci.nix deploy: split the forge's host decisions out of swarm.forge 2026-09-07 14:24:52 +02:00
hive-matrix.nix swarm: move the matrix packages to deploy, where their enable already lives 2026-09-07 20:46:37 +02:00
hive-network.nix docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
hive-priv.nix docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
hive-tls.nix docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
hyperhive.nix docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
local-defaults.nix bao: write the swarm controller's policy from inside the store 2026-09-07 18:43:09 +02:00
otel.nix deploy: move authelia's three host paths out of swarm.authelia 2026-09-07 15:44:07 +02:00
stylix-theme.nix swarm-ui: apply the operator's stylix theme, same as the dashboard already does 2026-08-24 14:28:25 +02:00
swarm-authelia.nix swarm: move both authelia packages to deploy 2026-09-07 20:46:38 +02:00
swarm-bao.nix bao: make the controller's CN an option, and give it cert options of its own 2026-09-07 22:12:27 +02:00
swarm-ca.nix swarm-ca: state the store-is-world-readable rule once, not three times 2026-09-02 09:03:35 +02:00
swarm-container-resolver.nix fix(#3363): swarm containers write their own resolver file 2026-08-17 17:30:15 +02:00
swarm-controller.nix swarm-controller: accept an agent's external matrix account and put it in the store 2026-09-08 15:53:50 +02:00
swarm-grafana.nix grafana: show which sources are shipping, not just that the store is up 2026-09-08 00:43:23 +02:00
swarm-nats.nix swarm: move the queue's responder package to deploy 2026-09-07 20:46:38 +02:00
swarm-otel.nix nix: split statusPublish and the otel secret into deploy.* 2026-09-07 16:54:23 +02:00
swarm-peers-removed.nix docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
swarm-required-services.nix deploy: rename enableAllLocalDefaults to deploy.singleHostSwarm 2026-08-30 20:12:16 +02:00
swarm-snapshot-store.nix deploy: move the wireguard mesh out of the namespace hives read 2026-09-07 14:24:52 +02:00
swarm-ui.nix swarm: move the controller's two packages to deploy 2026-09-07 20:46:38 +02:00
swarm-victorialogs.nix swarm: move both metric stores' package to deploy, and cover their shims 2026-09-07 20:46:38 +02:00
swarm-victoriametrics.nix swarm: move both metric stores' package to deploy, and cover their shims 2026-09-07 20:46:38 +02:00
swarm-wireguard.nix deploy: move the wireguard mesh out of the namespace hives read 2026-09-07 14:24:52 +02:00
swarm.nix nix: split statusPublish and the otel secret into deploy.* 2026-09-07 16:54:23 +02:00