hyperhive/nix/host-modules
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 9308752a09 hive-matrix: load the swarm's appservice and promote its sender
The matrix container renders the swarm registration before tuwunel starts
(`requiredBy` it, no network), tuwunel loads it as a second `.yaml`
credential, and a publish unit hands its token to the store. tuwunel 1.9.1
refuses only a duplicate id or as_token, not overlapping non-exclusive
namespaces, so it sits beside the hive's `hyperhive` registration.

`admin_execute` promotes exactly `@swarm` at boot. The module-eval pin
narrows from "no account" to that one list, compared whole so a second
entry fails; `admin_execute_errors_ignore` is pinned too. matrix-ctl may
write the swarm token's leaf, and the controller may only read it.

Everything is gated on matrix-ctl's store identity: with nobody to publish
the token, the registration would be an admin credential nobody reads.
2026-09-25 08:31:01 +02:00
..
hive-c0re swarm: default every queue URL to the queue's name on every hive 2026-09-24 17:26:31 +02:00
hive-forge hive-forge: a first authelia login creates the forge account 2026-09-25 08:29:56 +02:00
hive-gateway nix: ship the journals of the units an apply can leave failed 2026-09-24 15:14:44 +02:00
lib swarm: extract the name guards, so the module just says what is forbidden 2026-08-31 18:50:15 +02:00
swarm-grafana/dashboards swarm-grafana: replace busiest-agents bargauges with an actual table 2026-09-20 23:40:21 +02:00
default.nix nix: run the forge on one host per swarm (deploy.forgejo.enable) 2026-09-24 23:56:07 +02:00
deploy.nix nix: run the forge on one host per swarm (deploy.forgejo.enable) 2026-09-24 23:56:07 +02:00
glue-bao-readers-policy-order.nix swarm-bao: give the store forwarder's OIDC reader its own bao identity 2026-09-25 00:37:31 +02:00
glue-bao-tls.nix swarm-bao: give the store forwarder's OIDC reader its own bao identity 2026-09-25 00:37:31 +02:00
glue-controller-bao-identity.nix swarm-controller: hand the daemon the authority hives are issued from 2026-09-10 00:25:07 +02:00
glue-forge-oidc-client.nix nix: run the forge on one host per swarm (deploy.forgejo.enable) 2026-09-24 23:56:07 +02:00
glue-grafana-oidc-client.nix nix: run the forge on one host per swarm (deploy.forgejo.enable) 2026-09-24 23:56:07 +02:00
glue-matrix-bao-token.nix nix: move the reader-after-policy edges into their own colocation glue 2026-09-24 15:15:15 +02:00
glue-matrix-ctl-bao-identity.nix swarm-matrix-ctl: one control binary for the matrix container, not one per job 2026-09-20 22:07:16 +02:00
glue-nats-bao-identity.nix swarm-nats: give the queue a name, a bao-issued leaf, and require TLS 2026-09-24 17:26:31 +02:00
glue-queue-agent-credential.nix nix: move the reader-after-policy edges into their own colocation glue 2026-09-24 15:15:15 +02:00
glue-secret-publisher-bao-identity.nix swarm: publish minted OIDC client secrets into the swarm store 2026-09-12 11:22:33 +02:00
glue-services-issuer-bao-identity.nix nix: issue the swarm-services leaf from bao's pki mount 2026-09-23 21:00:02 +02:00
glue-swarm-bao-otel-oidc-client.nix nix: the store's own collector scrapes its metrics listener 2026-09-21 17:19:52 +02:00
glue-swarm-otel-oidc-client.nix swarm-otel: deliver the OIDC client secret through the secret store 2026-09-14 00:58:58 +02:00
hive-ci.nix nix: run the forge on one host per swarm (deploy.forgejo.enable) 2026-09-24 23:56:07 +02:00
hive-matrix.nix hive-matrix: load the swarm's appservice and promote its sender 2026-09-25 08:31:01 +02:00
hive-network.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
hive-priv.nix docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
hive-tls.nix nix: ship the journals of the units an apply can leave failed 2026-09-24 15:14:44 +02:00
hyperhive.nix docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
local-defaults.nix swarm: default every queue URL to the queue's name on every hive 2026-09-24 17:26:31 +02:00
otel.nix otel.nix: trim the StartLimit comment block to the load-bearing points 2026-09-23 17:22:51 +02:00
stylix-theme.nix swarm-ui: apply the operator's stylix theme, same as the dashboard already does 2026-08-24 14:28:25 +02:00
swarm-authelia.nix nix: make swarm.authelia.url non-nullable, trim its docs 2026-09-21 18:14:28 +02:00
swarm-bao-bootstrap-policy.hcl swarm-bao: give the store forwarder's OIDC reader its own bao identity 2026-09-25 00:37:31 +02:00
swarm-bao.nix hive-matrix: load the swarm's appservice and promote its sender 2026-09-25 08:31:01 +02:00
swarm-ca.nix nix: issue the swarm-services leaf from bao's pki mount 2026-09-23 21:00:02 +02:00
swarm-container-resolver.nix fix(#3363): swarm containers write their own resolver file 2026-08-17 17:30:15 +02:00
swarm-controller.nix nix: run the forge on one host per swarm (deploy.forgejo.enable) 2026-09-24 23:56:07 +02:00
swarm-grafana.nix nix: move the reader-after-policy edges into their own colocation glue 2026-09-24 15:15:15 +02:00
swarm-nats.nix swarm-nats: give the queue a name, a bao-issued leaf, and require TLS 2026-09-24 17:26:31 +02:00
swarm-otel.nix swarm-otel: correct the hostJournalDir comment for swarm-bao's exception 2026-09-25 04:02:08 +02:00
swarm-peers-removed.nix docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
swarm-required-services.nix nix: run the forge on one host per swarm (deploy.forgejo.enable) 2026-09-24 23:56:07 +02:00
swarm-secret-publisher.nix nix: the store's own collector scrapes its metrics listener 2026-09-21 17:19:52 +02:00
swarm-snapshot-store.nix deploy: move the wireguard mesh out of the namespace hives read 2026-09-07 14:24:52 +02:00
swarm-ui.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
swarm-victorialogs.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
swarm-victoriametrics.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
swarm-wireguard.nix deploy: move the wireguard mesh out of the namespace hives read 2026-09-07 14:24:52 +02:00
swarm.nix swarm-bao: give the store forwarder's OIDC reader its own bao identity 2026-09-25 00:37:31 +02:00