atlas
86652f051a
swarm: wire the agents' queue coordinates and credential through the modules
...
The host end: `HIVE_C0RE_AGENT_QUEUE_CREDENTIAL_DIR` tells the daemon
where the reader unit put the files, and a new
`deploy.hive-controller.queue.agentNatsUrl` says where the queue is as an
agent *container* reaches it. That address defaults to the bridge one and
never to loopback — `statusPublish.natsUrl` beside it is loopback and
correct, because hive-c0re shares the host netns and an agent does not.
Paired with the swarm's token endpoint, gated together, and forwarded by
`hive_c0re::meta` as both an env var and an agent option: the harness
reads the variable at runtime, its unit is built from the option.
The agent end: `nix/agent-modules/queue.nix` declares that option pair
and, when set, has the harness unit inherit the two credentials by name.
Bare-id `LoadCredential=` is the terse form documented for inheriting
what the service manager received, and is non-fatal when the credential
is absent — which a hive whose publisher has not run yet needs.
No `HIVE_AGENT_OIDC_CA_FILE`: the meta flake already embeds the hive CA
and the swarm root into each container's trust store at build time, and
reqwest's rustls backend verifies against it.
Refs #3805
2026-09-13 11:13:17 +02:00
..
hive-c0re
swarm: wire the agents' queue coordinates and credential through the modules
2026-09-13 11:13:17 +02:00
hive-forge
forge: move the forgejo package to deploy — slice 10 complete
2026-09-07 20:46:38 +02:00
hive-gateway
docs: matrix gateway vhost defaults to chat.<swarm-domain>, not matrix.<domain>
2026-09-07 16:53:22 +02:00
lib
swarm: extract the name guards, so the module just says what is forbidden
2026-08-31 18:50:15 +02:00
swarm-grafana /dashboards
grafana: switch the CLAUDE.md-size panel from a snapshot bar to a time series
2026-09-12 10:34:57 +02:00
default.nix
swarm: read the agent queue credential out of the store onto the hive host
2026-09-12 21:05:52 +02:00
deploy.nix
forge: move the forgejo package to deploy — slice 10 complete
2026-09-07 20:46:38 +02:00
glue-bao-tls.nix
swarm: publish minted OIDC client secrets into the swarm store
2026-09-12 11:22:33 +02:00
glue-controller-bao-identity.nix
swarm-controller: hand the daemon the authority hives are issued from
2026-09-10 00:25:07 +02:00
glue-matrix-bao-token.nix
swarm: put the matrix registration token where the reader is granted
2026-09-12 19:46:04 +02:00
glue-queue-agent-credential.nix
swarm: run the agent queue credential reader before hive-c0re
2026-09-13 11:10:00 +02:00
glue-secret-publisher-bao-identity.nix
swarm: publish minted OIDC client secrets into the swarm store
2026-09-12 11:22:33 +02:00
hive-ci.nix
deploy: split the forge's host decisions out of swarm.forge
2026-09-07 14:24:52 +02:00
hive-matrix.nix
swarm: move the matrix packages to deploy, where their enable already lives
2026-09-07 20:46:37 +02:00
hive-network.nix
docs: restructure into topic subdirectories, collapse duplicated index
2026-09-02 01:55:37 +02:00
hive-priv.nix
docs: restructure into topic subdirectories, collapse duplicated index
2026-09-02 01:55:37 +02:00
hive-tls.nix
docs: restructure into topic subdirectories, collapse duplicated index
2026-09-02 01:55:37 +02:00
hyperhive.nix
docs: restructure into topic subdirectories, collapse duplicated index
2026-09-02 01:55:37 +02:00
local-defaults.nix
bao: write the swarm controller's policy from inside the store
2026-09-07 18:43:09 +02:00
otel.nix
otel: scrape each collector's own loss counters
2026-09-12 10:34:06 +02:00
stylix-theme.nix
swarm-ui: apply the operator's stylix theme, same as the dashboard already does
2026-08-24 14:28:25 +02:00
swarm-authelia.nix
swarm: name the agent client after its hive, not after "agent"
2026-09-12 10:33:06 +02:00
swarm-bao.nix
swarm-bao: write the secret publisher's policy and cert-auth role
2026-09-12 10:56:50 +02:00
swarm-ca.nix
swarm-ca: state the store-is-world-readable rule once, not three times
2026-09-02 09:03:35 +02:00
swarm-container-resolver.nix
fix( #3363 ): swarm containers write their own resolver file
2026-08-17 17:30:15 +02:00
swarm-controller.nix
swarm-controller: hand the daemon the authority hives are issued from
2026-09-10 00:25:07 +02:00
swarm-grafana.nix
swarm-grafana: grafana requires SSO, so the login form goes unconditionally
2026-09-11 18:23:51 +02:00
swarm-nats.nix
swarm-nats: set max_payload to 8 MiB explicitly
2026-09-12 21:40:36 +02:00
swarm-otel.nix
hive-c0re: name an agent container after its machine, not "nixos"
2026-09-12 18:19:18 +02:00
swarm-peers-removed.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm-required-services.nix
deploy: rename enableAllLocalDefaults to deploy.singleHostSwarm
2026-08-30 20:12:16 +02:00
swarm-secret-publisher.nix
swarm: log in to bao before reading or writing a secret
2026-09-12 12:27:33 +02:00
swarm-snapshot-store.nix
deploy: move the wireguard mesh out of the namespace hives read
2026-09-07 14:24:52 +02:00
swarm-ui.nix
swarm: move the controller's two packages to deploy
2026-09-07 20:46:38 +02:00
swarm-victorialogs.nix
swarm-nats, swarm-victorialogs: correct two comments that describe a topology we do not have
2026-09-10 23:18:40 +02:00
swarm-victoriametrics.nix
swarm: move both metric stores' package to deploy, and cover their shims
2026-09-07 20:46:38 +02:00
swarm-wireguard.nix
deploy: move the wireguard mesh out of the namespace hives read
2026-09-07 14:24:52 +02:00
swarm.nix
swarm: wire the agents' queue coordinates and credential through the modules
2026-09-13 11:13:17 +02:00