Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/nix/host-modules
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 97fb76ce99 matrix: the agent's daemon pulls its linked accounts from bao itself
hive-matrix-daemon now learns which external matrix accounts it has from
the swarm secret store, under the agent's own certificate, and the hive
push chain for matrix is gone.

The daemon lists swarm/agents/<agent>/matrix/ (the `list` its policy
grants on its own metadata subtree), reads each account's homeserver
from its credential, and brings the accounts up with their tokens from
the store. Every two minutes it lists again and exits with 75 when the
set of linked accounts changed; the unit restarts on 75 without counting
a failure. A listed name whose credential reads as absent is skipped and
logged once. At start it removes the matrix-token-<a> /
matrix-account-<a>.json pairs a hive delivered (a sidecar marks a pair
as delivered; a declared tokenFile keeps its token).

Removed: CredentialNotice and the $SWARM.credential.* subject and NATS
grant, the controller's publish and its queue precondition on the PUT
route, hive-c0re's credential subscription arm and workers/credential.rs,
priv_client::write_agent_matrix_token, hive-priv's WriteAgentMatrixToken
and its helpers, and the daemon's state-dir account discovery.

Kept: WriteAgentGithubToken and the external-forge path
(WriteAgentExtraForgeAccount, extra_forges.rs) are untouched, and a
declared matrixAccounts tokenFile is still read when the store has no
token for that account.

Refs #4348
2026-10-01 17:43:28 +02:00
..
hive-c0re matrix: the agent's daemon pulls its linked accounts from bao itself 2026-10-01 17:43:28 +02:00
hive-forge nix: split hive-forge into service and deploy-mode files 2026-10-01 13:00:52 +02:00
hive-gateway swarm-otel: ship the whole host journal, drop user sessions after it 2026-09-30 23:01:49 +02:00
lib refresh-consumer: key the restart on the file's mtime, not a pre-write compare 2026-09-30 07:45:47 +02:00
swarm-grafana/dashboards hive-agent: export ACP-reported cost and context fill over OTLP 2026-09-30 22:24:06 +02:00
bao-bootstrap-policy.hcl bao: disable the unused approle auth method, declaratively 2026-09-28 22:58:36 +02:00
default.nix nix: split swarm-otel into service and deploy-mode files 2026-10-01 13:00:40 +02:00
deploy.nix nix: split hive-forge into service and deploy-mode files 2026-10-01 13:00:52 +02:00
glue-bao-readers-policy-order.nix swarm-bao: write every swarm-* grant as a bao granter, not with a 24h token 2026-09-27 22:57:46 +02:00
glue-bao-tls.nix swarm-otel: ship the whole host journal, drop user sessions after it 2026-09-30 23:01:49 +02:00
glue-bao-ui-oidc-client.nix bao: OIDC login to the browser UI via authelia, as a metadata-only viewer 2026-09-28 19:56:38 +02:00
glue-controller-bao-identity.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
glue-forge-oidc-client.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
glue-grafana-oidc-client.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
glue-matrix-bao-token.nix swarm-otel: ship the whole host journal, drop user sessions after it 2026-09-30 23:01:49 +02:00
glue-matrix-ctl-bao-identity.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
glue-nats-auth-bao-identity.nix swarm-nats-auth: verify an agent's own token against the store 2026-09-28 08:24:52 +02:00
glue-nats-bao-identity.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
glue-queue-agent-credential.nix swarm-otel: ship the whole host journal, drop user sessions after it 2026-09-30 23:01:49 +02:00
glue-secret-publisher-bao-identity.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
glue-services-issuer-bao-identity.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
glue-swarm-bao-otel-oidc-client.nix ops: update option pointers after grafana/bao split 2026-10-01 09:53:04 +02:00
glue-swarm-otel-oidc-client.nix ops: update option pointers after otel split 2026-10-01 13:00:40 +02:00
hive-ci.nix swarm-otel: ship the whole host journal, drop user sessions after it 2026-09-30 23:01:49 +02:00
hive-matrix-service.nix nix: split hive-matrix into service and deploy-mode files 2026-10-01 13:00:25 +02:00
hive-matrix.nix nix: split hive-matrix into service and deploy-mode files 2026-10-01 13:00:25 +02:00
hive-network.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
hive-priv.nix hive-priv: create agent socket dirs on start; drop hyperhive-agents.conf 2026-09-27 18:55:33 +02:00
hive-tls.nix swarm-otel: ship the whole host journal, drop user sessions after it 2026-09-30 23:01:49 +02:00
hyperhive.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
local-defaults.nix swarm-controller: read the queue client secret from the store, drop the file 2026-09-28 19:01:05 +02:00
otel.nix ops: update option pointers after otel split 2026-10-01 13:00:40 +02:00
stylix-theme.nix swarm-ui: apply the operator's stylix theme, same as the dashboard already does 2026-08-24 14:28:25 +02:00
swarm-authelia-service.nix nix: split swarm-authelia into service and deploy-mode files 2026-10-01 10:25:19 +02:00
swarm-authelia.nix ops: cross-reference authelia unit literals in both split files 2026-10-01 10:28:57 +02:00
swarm-bao-service.nix nix: split swarm-bao into service and deploy-mode files 2026-10-01 09:37:36 +02:00
swarm-bao.nix nix: split swarm-bao into service and deploy-mode files 2026-10-01 09:37:36 +02:00
swarm-ca.nix swarm-otel: ship the whole host journal, drop user sessions after it 2026-09-30 23:01:49 +02:00
swarm-controller.nix swarm-otel: ship the whole host journal, drop user sessions after it 2026-09-30 23:01:49 +02:00
swarm-grafana-service.nix nix: split swarm-grafana into service and deploy-mode files 2026-10-01 09:30:21 +02:00
swarm-grafana.nix nix: split swarm-grafana into service and deploy-mode files 2026-10-01 09:30:21 +02:00
swarm-nats-service.nix nix: split swarm-bao into service and deploy-mode files 2026-10-01 09:37:36 +02:00
swarm-nats.nix nix: split swarm-nats into service and deploy-mode files 2026-10-01 09:04:35 +02:00
swarm-otel-service.nix nix: split swarm-otel into service and deploy-mode files 2026-10-01 13:00:40 +02:00
swarm-otel.nix ops: update option pointers after otel split 2026-10-01 13:00:40 +02:00
swarm-peers-removed.nix docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
swarm-required-services.nix nix: run the forge on one host per swarm (deploy.forgejo.enable) 2026-09-24 23:56:07 +02:00
swarm-secret-publisher.nix swarm-otel: ship the whole host journal, drop user sessions after it 2026-09-30 23:01:49 +02:00
swarm-snapshot-store.nix deploy: move the wireguard mesh out of the namespace hives read 2026-09-07 14:24:52 +02:00
swarm-ui.nix ops: update option pointers after otel split 2026-10-01 13:00:40 +02:00
swarm-victorialogs-service.nix nix: split swarm-victorialogs into service and deploy-mode files 2026-10-01 10:03:55 +02:00
swarm-victorialogs.nix nix: split swarm-victorialogs into service and deploy-mode files 2026-10-01 10:03:55 +02:00
swarm-victoriametrics-service.nix nix: split swarm-victoriametrics into service and deploy-mode files 2026-10-01 10:03:55 +02:00
swarm-victoriametrics.nix nix: split swarm-victoriametrics into service and deploy-mode files 2026-10-01 10:03:55 +02:00
swarm-wireguard.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
swarm.nix bao: serve the browser UI to admins via a loopback-only listener 2026-09-28 19:31:02 +02:00