atlas
97fb76ce99
matrix: the agent's daemon pulls its linked accounts from bao itself
...
hive-matrix-daemon now learns which external matrix accounts it has from
the swarm secret store, under the agent's own certificate, and the hive
push chain for matrix is gone.
The daemon lists swarm/agents/<agent>/matrix/ (the `list` its policy
grants on its own metadata subtree), reads each account's homeserver
from its credential, and brings the accounts up with their tokens from
the store. Every two minutes it lists again and exits with 75 when the
set of linked accounts changed; the unit restarts on 75 without counting
a failure. A listed name whose credential reads as absent is skipped and
logged once. At start it removes the matrix-token-<a> /
matrix-account-<a>.json pairs a hive delivered (a sidecar marks a pair
as delivered; a declared tokenFile keeps its token).
Removed: CredentialNotice and the $SWARM.credential.* subject and NATS
grant, the controller's publish and its queue precondition on the PUT
route, hive-c0re's credential subscription arm and workers/credential.rs,
priv_client::write_agent_matrix_token, hive-priv's WriteAgentMatrixToken
and its helpers, and the daemon's state-dir account discovery.
Kept: WriteAgentGithubToken and the external-forge path
(WriteAgentExtraForgeAccount, extra_forges.rs) are untouched, and a
declared matrixAccounts tokenFile is still read when the store has no
token for that account.
Refs #4348
2026-10-01 17:43:28 +02:00
..
hive-c0re
matrix: the agent's daemon pulls its linked accounts from bao itself
2026-10-01 17:43:28 +02:00
hive-forge
nix: split hive-forge into service and deploy-mode files
2026-10-01 13:00:52 +02:00
hive-gateway
swarm-otel: ship the whole host journal, drop user sessions after it
2026-09-30 23:01:49 +02:00
lib
refresh-consumer: key the restart on the file's mtime, not a pre-write compare
2026-09-30 07:45:47 +02:00
swarm-grafana /dashboards
hive-agent: export ACP-reported cost and context fill over OTLP
2026-09-30 22:24:06 +02:00
bao-bootstrap-policy.hcl
bao: disable the unused approle auth method, declaratively
2026-09-28 22:58:36 +02:00
default.nix
nix: split swarm-otel into service and deploy-mode files
2026-10-01 13:00:40 +02:00
deploy.nix
nix: split hive-forge into service and deploy-mode files
2026-10-01 13:00:52 +02:00
glue-bao-readers-policy-order.nix
swarm-bao: write every swarm-* grant as a bao granter, not with a 24h token
2026-09-27 22:57:46 +02:00
glue-bao-tls.nix
swarm-otel: ship the whole host journal, drop user sessions after it
2026-09-30 23:01:49 +02:00
glue-bao-ui-oidc-client.nix
bao: OIDC login to the browser UI via authelia, as a metadata-only viewer
2026-09-28 19:56:38 +02:00
glue-controller-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-forge-oidc-client.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-grafana-oidc-client.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-matrix-bao-token.nix
swarm-otel: ship the whole host journal, drop user sessions after it
2026-09-30 23:01:49 +02:00
glue-matrix-ctl-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-nats-auth-bao-identity.nix
swarm-nats-auth: verify an agent's own token against the store
2026-09-28 08:24:52 +02:00
glue-nats-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-queue-agent-credential.nix
swarm-otel: ship the whole host journal, drop user sessions after it
2026-09-30 23:01:49 +02:00
glue-secret-publisher-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-services-issuer-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-swarm-bao-otel-oidc-client.nix
ops: update option pointers after grafana/bao split
2026-10-01 09:53:04 +02:00
glue-swarm-otel-oidc-client.nix
ops: update option pointers after otel split
2026-10-01 13:00:40 +02:00
hive-ci.nix
swarm-otel: ship the whole host journal, drop user sessions after it
2026-09-30 23:01:49 +02:00
hive-matrix-service.nix
nix: split hive-matrix into service and deploy-mode files
2026-10-01 13:00:25 +02:00
hive-matrix.nix
nix: split hive-matrix into service and deploy-mode files
2026-10-01 13:00:25 +02:00
hive-network.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
hive-priv.nix
hive-priv: create agent socket dirs on start; drop hyperhive-agents.conf
2026-09-27 18:55:33 +02:00
hive-tls.nix
swarm-otel: ship the whole host journal, drop user sessions after it
2026-09-30 23:01:49 +02:00
hyperhive.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
local-defaults.nix
swarm-controller: read the queue client secret from the store, drop the file
2026-09-28 19:01:05 +02:00
otel.nix
ops: update option pointers after otel split
2026-10-01 13:00:40 +02:00
stylix-theme.nix
swarm-ui: apply the operator's stylix theme, same as the dashboard already does
2026-08-24 14:28:25 +02:00
swarm-authelia-service.nix
nix: split swarm-authelia into service and deploy-mode files
2026-10-01 10:25:19 +02:00
swarm-authelia.nix
ops: cross-reference authelia unit literals in both split files
2026-10-01 10:28:57 +02:00
swarm-bao-service.nix
nix: split swarm-bao into service and deploy-mode files
2026-10-01 09:37:36 +02:00
swarm-bao.nix
nix: split swarm-bao into service and deploy-mode files
2026-10-01 09:37:36 +02:00
swarm-ca.nix
swarm-otel: ship the whole host journal, drop user sessions after it
2026-09-30 23:01:49 +02:00
swarm-controller.nix
swarm-otel: ship the whole host journal, drop user sessions after it
2026-09-30 23:01:49 +02:00
swarm-grafana-service.nix
nix: split swarm-grafana into service and deploy-mode files
2026-10-01 09:30:21 +02:00
swarm-grafana.nix
nix: split swarm-grafana into service and deploy-mode files
2026-10-01 09:30:21 +02:00
swarm-nats-service.nix
nix: split swarm-bao into service and deploy-mode files
2026-10-01 09:37:36 +02:00
swarm-nats.nix
nix: split swarm-nats into service and deploy-mode files
2026-10-01 09:04:35 +02:00
swarm-otel-service.nix
nix: split swarm-otel into service and deploy-mode files
2026-10-01 13:00:40 +02:00
swarm-otel.nix
ops: update option pointers after otel split
2026-10-01 13:00:40 +02:00
swarm-peers-removed.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm-required-services.nix
nix: run the forge on one host per swarm (deploy.forgejo.enable)
2026-09-24 23:56:07 +02:00
swarm-secret-publisher.nix
swarm-otel: ship the whole host journal, drop user sessions after it
2026-09-30 23:01:49 +02:00
swarm-snapshot-store.nix
deploy: move the wireguard mesh out of the namespace hives read
2026-09-07 14:24:52 +02:00
swarm-ui.nix
ops: update option pointers after otel split
2026-10-01 13:00:40 +02:00
swarm-victorialogs-service.nix
nix: split swarm-victorialogs into service and deploy-mode files
2026-10-01 10:03:55 +02:00
swarm-victorialogs.nix
nix: split swarm-victorialogs into service and deploy-mode files
2026-10-01 10:03:55 +02:00
swarm-victoriametrics-service.nix
nix: split swarm-victoriametrics into service and deploy-mode files
2026-10-01 10:03:55 +02:00
swarm-victoriametrics.nix
nix: split swarm-victoriametrics into service and deploy-mode files
2026-10-01 10:03:55 +02:00
swarm-wireguard.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
swarm.nix
bao: serve the browser UI to admins via a loopback-only listener
2026-09-28 19:31:02 +02:00