hyperhive/nix/host-modules
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 9bbc74ee51 glue-bao-tls: mint the store an identity it can hold before it is up
A CA that signs exactly two things -- the store's server certificate and
the client certificate of whoever reads from it -- and distributes
nothing. Not the hive CA, not the swarm CA: the store will distribute
both, and an authority you must already hold a certificate from cannot
be one the store hands out. Not the gateway's HTTPS material either,
self-signed or ACME; that is a different trust domain with a different
audience.

The minting lives here rather than in swarm-bao.nix because it is an
opinion about where the store's identity comes from -- the most
consequential one available. The service serves what it is handed. A
deployment with a real internal CA drops this file and names its own
paths in serverCertFile / clientCaFile, and nothing in the store
changes. Ordering simplifies too: with the unit and its consumer in one
module, before/requiredBy is internal rather than a cross-module fact.

Idempotent on ABSENCE only. Re-issuing the CA invalidates every client
certificate already trusting it, so a rebuild that refreshed it would
lock out every reader in the swarm at once.
2026-08-30 19:01:10 +02:00
..
hive-c0re matrix: forward the homeserver URL from client hives too 2026-08-30 15:17:02 +02:00
hive-forge deploy: move the forge CI runner toggle out of swarm 2026-08-30 16:07:21 +02:00
hive-gateway gateway: move verifiedProxyTo's 42-line rationale comment to docs/gateway.md 2026-08-28 10:48:26 +02:00
lib fix(#3527): a missing source must report as zero, not as empty 2026-08-19 20:27:00 +02:00
swarm-grafana/dashboards grafana: rank the by-label panel as bars, and stop calling it open issues 2026-08-28 13:23:25 +02:00
default.nix glue-bao-tls: mint the store an identity it can hold before it is up 2026-08-30 19:01:10 +02:00
deploy.nix deploy: which host runs the secret store is its own decision 2026-08-30 18:54:35 +02:00
glue-bao-tls.nix glue-bao-tls: mint the store an identity it can hold before it is up 2026-08-30 19:01:10 +02:00
hive-ci.nix deploy: move the forge CI runner toggle out of swarm 2026-08-30 16:07:21 +02:00
hive-matrix.nix deploy: move the matrix homeserver toggle out of swarm 2026-08-30 15:17:02 +02:00
hive-network.nix require network isolation, deleting the residual non-isolated branch 2026-08-30 03:32:08 +02:00
hive-priv.nix fix(#2573): also add /etc/tmpfiles.d to hive-priv ReadWritePaths (same EROFS class) 2026-07-18 16:39:20 +02:00
hive-tls.nix deploy: give every option an enable, and name the controller one 2026-08-30 04:23:22 +02:00
hyperhive.nix refactor(nix): a hive's domain comes out of the swarm directory 2026-08-05 22:43:17 +02:00
local-defaults.nix local-defaults: assert the controller through deploy, not the old alias 2026-08-30 04:23:22 +02:00
otel.nix deploy: name the swarm collector swarm-otel, not otel 2026-08-30 04:23:22 +02:00
stylix-theme.nix swarm-ui: apply the operator's stylix theme, same as the dashboard already does 2026-08-24 14:28:25 +02:00
swarm-authelia.nix deploy: name the swarm collector swarm-otel, not otel 2026-08-30 04:23:22 +02:00
swarm-bao.nix swarm-bao: run the swarm's secret store in a container 2026-08-30 19:01:10 +02:00
swarm-ca.nix swarm-otel: collect only the units the swarm's services declare 2026-08-24 22:05:45 +02:00
swarm-container-resolver.nix fix(#3363): swarm containers write their own resolver file 2026-08-17 17:30:15 +02:00
swarm-controller.nix deploy: name the swarm collector swarm-otel, not otel 2026-08-30 04:23:22 +02:00
swarm-grafana.nix deploy: name the swarm collector swarm-otel, not otel 2026-08-30 04:23:22 +02:00
swarm-nats.nix deploy: name the swarm collector swarm-otel, not otel 2026-08-30 04:23:22 +02:00
swarm-otel.nix deploy: name the swarm collector swarm-otel, not otel 2026-08-30 04:23:22 +02:00
swarm-peers-removed.nix docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
swarm-required-services.nix deploy: which host runs the secret store is its own decision 2026-08-30 18:54:35 +02:00
swarm-snapshot-store.nix refactor(#2862): keep the option at services.hyperhive.snapshotStore 2026-07-31 19:03:24 +02:00
swarm-ui.nix deploy: give every option an enable, and name the controller one 2026-08-30 04:23:22 +02:00
swarm-victorialogs.nix deploy: retention is the store host's decision, not the swarm's 2026-08-30 16:23:48 +02:00
swarm-victoriametrics.nix deploy: retention is the store host's decision, not the swarm's 2026-08-30 16:23:48 +02:00
swarm-wireguard.nix docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
swarm.nix deploy: name the swarm collector swarm-otel, not otel 2026-08-30 04:23:22 +02:00