Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/nix/agent-modules
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 8e23feb01b github: PATs live in swarm bao; the agent fetches them itself
An operator links an agent's GitHub personal access token in the swarm UI
(LinkGithubAccountForm, "link github account" on /agents). swarm-controller's
PUT /api/hives/{hive}/agents/{agent}/github-account stores it at
swarm/agents/<agent>/github-token (swarm_secret_client::github), a flat leaf
under the agent's prefix that the agent's existing read grant already covers:
no policy change, and no list grant, since there is one token per agent.

In the agent, hive-agent-github-token (oneshot + 2-minute timer, as the agent
user, under its own store certificate, ordered before hive-github-notify)
reads that path and writes <state>/github-token, 0600 and agent-owned, the
file the gh wrapper, git credential helper and hive-github-notify already
read. It replaces the file by rename only when the bytes changed and never
deletes it: a hive-written github-token stays until a token is linked in the
swarm UI. It is installed only with a store address and
services.hyperhive.agent.github.enable.

Removed: the dashboard's CR3D3NTIALS page (credentials.html/js/css, its
build entries and H0M3 tile; GITHUB was its only tab), hive-c0re's
dashboard/matrix_accounts.rs with GET/POST /api/github-account,
priv_client::write_agent_github_token, the host socket's
SetAgentGithubToken and `hivectl github set-token`, and hive-priv's
WriteAgentGithubToken with write_agent_state_file, its only caller gone.

Docs: integrations/github.md and swarm/ui.md describe the swarm path,
swarm/credentials.md gains the store-path row, and the hive UI docs,
hivectl docs and security.md's hive-priv table drop the removed pieces.

Closes #4347
2026-10-02 17:48:27 +02:00
..
agent-service.nix docs(turn-loop): move harness systemd unit shape out of agent-roster.md 2026-10-02 14:47:31 +02:00
bao.nix credential units: 24h retry shape; start a failed nginx when the cert lands 2026-09-30 07:45:47 +02:00
bash-env.nix nix: move the agent option namespace under services.hyperhive.agent 2026-09-17 20:19:30 +02:00
claude-settings.nix agent: make claudePlugins additive instead of replacing 2026-09-19 10:48:29 +02:00
dashboard-links.nix nix: move the agent option namespace under services.hyperhive.agent 2026-09-17 20:19:30 +02:00
default.nix github: PATs live in swarm bao; the agent fetches them itself 2026-10-02 17:48:27 +02:00
docs.nix nix: move the agent option namespace under services.hyperhive.agent 2026-09-17 20:19:30 +02:00
forge-accounts.nix forge: external forge accounts live in swarm bao; the agent fetches them itself 2026-10-01 18:05:33 +02:00
forge-token.nix credential units: 24h retry shape; start a failed nginx when the cert lands 2026-09-30 07:45:47 +02:00
forge.nix fix(forge): pass avatar image via files, not argv (E2BIG over 128 KiB) 2026-09-30 19:17:59 +02:00
frontend.nix nix: move the agent option namespace under services.hyperhive.agent 2026-09-17 20:19:30 +02:00
github-token.nix github: PATs live in swarm bao; the agent fetches them itself 2026-10-02 17:48:27 +02:00
github.nix github: PATs live in swarm bao; the agent fetches them itself 2026-10-02 17:48:27 +02:00
logs.nix nix: move the agent option namespace under services.hyperhive.agent 2026-09-17 20:19:30 +02:00
matrix.nix matrix: the agent's daemon pulls its linked accounts from bao itself 2026-10-01 17:43:28 +02:00
mcp.nix hive-runtime: read the ACP provider key from bao 2026-09-30 22:55:03 +02:00
network.nix agents: pull the forge token from bao; drop tea-login 2026-09-24 17:48:53 +02:00
otel.nix swarm-otel: ship the whole host journal, drop user sessions after it 2026-09-30 23:01:49 +02:00
packages.nix nix: move the agent option namespace under services.hyperhive.agent 2026-09-17 20:19:30 +02:00
queue-identity.nix hive-agent: read the per-agent queue secret from bao in process 2026-09-29 10:18:07 +02:00
queue.nix swarm-nats: give the queue a name, a bao-issued leaf, and require TLS 2026-09-24 17:26:31 +02:00
renamed-options.nix matrix: drop the per-agent matrix.enable; accounts are the enable signal 2026-09-18 10:35:16 +02:00
screen.nix nix: move the agent option namespace under services.hyperhive.agent 2026-09-17 20:19:30 +02:00
user.nix hive-priv: create agent socket dirs on start; drop hyperhive-agents.conf 2026-09-27 18:55:33 +02:00
weston-vnc.nix nix: move the agent option namespace under services.hyperhive.agent 2026-09-17 20:19:30 +02:00