hyperhive/nix/host-modules
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 922f91cb7d swarm-authelia: stop answering machine callers with a 200 error page
The authelia vhost intercepts upstream errors and serves a friendly
"SSO unavailable" page. The `=` form of `error_page` takes its status
from the redirected location, and that location serves a file -- so the
page is returned as **200**.

That is right for a human typing the URL and wrong for every machine
caller, all of which reach authelia through this same vhost by name:

  - `/api/authz/auth-request` -- nginx `auth_request` treats any 2xx as
    success, so a down authelia means access GRANTED
  - `/api/oidc/introspection` -- a token check answering 200
  - `/api/oidc/token`, `/.well-known/openid-configuration` -- clients
    parsing an HTML error page as their JSON document

Routes `/api/` and `/.well-known/` without the interception. A longer
prefix wins over `/`, and the intercept directives live inside the `/`
location rather than at server level, so they do not reach the new ones.

Split by AUDIENCE rather than by an enumerated path list: a human still
gets the page, and every machine caller -- including the login page's own
XHR, and any endpoint added later -- gets the real status.

Measured against a real nginx with a dead upstream, both arms: machine
paths return 502 where they returned 200+HTML, a subrequest through the
new prefix denies (matching a direct port dial) where through `/` it
served the protected content, and the browser control confirms the
friendly page survives. URI preservation checked separately against a
live echo upstream -- `proxy_pass` with no URI part passes the full
original path.
2026-08-27 14:04:18 +02:00
..
hive-c0re swarm-otel: collect only the units the swarm's services declare 2026-08-24 22:05:45 +02:00
hive-forge hive-forge: enable the per-label and per-repository issue metrics 2026-08-27 00:16:04 +02:00
hive-gateway swarm-otel: collect only the units the swarm's services declare 2026-08-24 22:05:45 +02:00
lib fix(#3527): a missing source must report as zero, not as empty 2026-08-19 20:27:00 +02:00
swarm-grafana/dashboards swarm-grafana: provision log store and metrics store dashboards 2026-08-26 21:37:31 +02:00
default.nix feat(swarm-victorialogs): a log store for the swarm 2026-08-24 16:36:18 +02:00
hive-ci.nix hive-ci: run the runner credential precondition with full privileges 2026-08-26 22:47:31 +02:00
hive-matrix.nix forge, matrix: SSO is not optional 2026-08-24 23:06:25 +02:00
hive-network.nix docs(network): drop the otel reasoning instead of restating it 2026-08-19 02:04:57 +02:00
hive-priv.nix fix(#2573): also add /etc/tmpfiles.d to hive-priv ReadWritePaths (same EROFS class) 2026-07-18 16:39:20 +02:00
hive-tls.nix fix(#3462): apply the name check in the unit that runs on the deploy 2026-08-18 21:54:38 +02:00
hyperhive.nix refactor(nix): a hive's domain comes out of the swarm directory 2026-08-05 22:43:17 +02:00
local-defaults.nix fix(#3343): move the all-local queue derivations into the deployment mode 2026-08-16 19:37:49 +02:00
otel.nix otel: give host metrics a host identity via resourcedetection 2026-08-27 10:49:30 +02:00
stylix-theme.nix swarm-ui: apply the operator's stylix theme, same as the dashboard already does 2026-08-24 14:28:25 +02:00
swarm-authelia.nix swarm-authelia: stop answering machine callers with a 200 error page 2026-08-27 14:04:18 +02:00
swarm-ca.nix swarm-otel: collect only the units the swarm's services declare 2026-08-24 22:05:45 +02:00
swarm-container-resolver.nix fix(#3363): swarm containers write their own resolver file 2026-08-17 17:30:15 +02:00
swarm-controller.nix swarm-otel: collect only the units the swarm's services declare 2026-08-24 22:05:45 +02:00
swarm-grafana.nix swarm-grafana: provision log store and metrics store dashboards 2026-08-26 21:37:31 +02:00
swarm-nats.nix swarm-nats: manual callout needs all four keys, not two 2026-08-24 23:06:59 +02:00
swarm-otel.nix swarm-otel: request the bearer-authz scope on the metrics scrape 2026-08-26 18:34:21 +02:00
swarm-peers-removed.nix docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
swarm-required-services.nix feat(swarm): start the log store with the other required services 2026-08-24 17:00:38 +02:00
swarm-snapshot-store.nix refactor(#2862): keep the option at services.hyperhive.snapshotStore 2026-07-31 19:03:24 +02:00
swarm-ui.nix swarm-ui: swap colors.css via a plain nginx location, not a package-copy derivation 2026-08-24 14:28:25 +02:00
swarm-victorialogs.nix swarm-otel: collect only the units the swarm's services declare 2026-08-24 22:05:45 +02:00
swarm-victoriametrics.nix swarm-otel: collect only the units the swarm's services declare 2026-08-24 22:05:45 +02:00
swarm-wireguard.nix docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
swarm.nix swarm: publish an authenticated gateway vhost for VictoriaLogs 2026-08-24 18:43:26 +02:00