atlas
9bad58d86d
swarm-nats-auth: verify an agent's own token against the store
...
An `auth_token` spelled `swarm-agent.<agent>.<secret>` is no longer sent
to introspection. The responder reads `swarm/agents/<agent>/queue` with
an identity of its own, checks that the stored object names the same
agent, compares the secret in constant time, and grants the subjects
`--agent-token-publish-subject` lists with `{agent}` expanded. Every
other outcome denies: a malformed token, no store identity, nothing
stored, a failed or slow lookup, a different secret. A token without
the prefix takes the OIDC path unchanged.
The journal's `auth request` line names such a caller `agent:<agent>`;
the hive-shared credential keeps `hive-<h>-agent`.
The new principal: a `swarm-nats-auth` cert-auth role and policy with
read on `secret/data/swarm/agents/+/queue` alone, a leaf signed by the
store's PKI glue, and `glue-nats-auth-bao-identity.nix` pairing the two.
The copy unit delivers the identity into the queue's container, and an
absent leaf is delivered empty so the responder still starts and only
agent tokens are refused.
The policy and role are written by `swarm-bao-nats-auth-policy`, logged in
as the bao granter: both names fall under its `swarm-*` globs, so the
deploy writes them with no operator step. module-eval counts it among the
granting units, so every generic granting-unit case covers it.
The secret compare uses `subtle`, already in the lock file through the
TLS stack; no workspace crate offered one directly.
2026-09-28 08:24:52 +02:00
..
hive-c0re
hive-priv: create agent socket dirs on start; drop hyperhive-agents.conf
2026-09-27 18:55:33 +02:00
hive-forge
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
hive-gateway
hive-priv: create agent socket dirs on start; drop hyperhive-agents.conf
2026-09-27 18:55:33 +02:00
lib
lint: tighten atomic-write-secret.nix's header comment; fix vale contractions in persistence.md
2026-09-26 21:50:03 +02:00
swarm-grafana /dashboards
swarm-grafana: replace busiest-agents bargauges with an actual table
2026-09-20 23:40:21 +02:00
bao-bootstrap-policy.hcl
swarm-bao: write every swarm-* grant as a bao granter, not with a 24h token
2026-09-27 22:57:46 +02:00
default.nix
swarm-nats-auth: verify an agent's own token against the store
2026-09-28 08:24:52 +02:00
deploy.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-bao-readers-policy-order.nix
swarm-bao: write every swarm-* grant as a bao granter, not with a 24h token
2026-09-27 22:57:46 +02:00
glue-bao-tls.nix
swarm-nats-auth: verify an agent's own token against the store
2026-09-28 08:24:52 +02:00
glue-controller-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-forge-oidc-client.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-grafana-oidc-client.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-matrix-bao-token.nix
host-modules: atomic_write_secret takes the value as an argument, not stdin
2026-09-26 21:50:03 +02:00
glue-matrix-ctl-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-nats-auth-bao-identity.nix
swarm-nats-auth: verify an agent's own token against the store
2026-09-28 08:24:52 +02:00
glue-nats-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-queue-agent-credential.nix
host-modules: atomic_write_secret takes the value as an argument, not stdin
2026-09-26 21:50:03 +02:00
glue-secret-publisher-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-services-issuer-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-swarm-bao-otel-oidc-client.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-swarm-otel-oidc-client.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
hive-ci.nix
nix: run the forge on one host per swarm (deploy.forgejo.enable)
2026-09-24 23:56:07 +02:00
hive-matrix.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
hive-network.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
hive-priv.nix
hive-priv: create agent socket dirs on start; drop hyperhive-agents.conf
2026-09-27 18:55:33 +02:00
hive-tls.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
hyperhive.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
local-defaults.nix
swarm: default every queue URL to the queue's name on every hive
2026-09-24 17:26:31 +02:00
otel.nix
otel.nix: trim the StartLimit comment block to the load-bearing points
2026-09-23 17:22:51 +02:00
stylix-theme.nix
swarm-ui: apply the operator's stylix theme, same as the dashboard already does
2026-08-24 14:28:25 +02:00
swarm-authelia.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
swarm-bao.nix
swarm-nats-auth: verify an agent's own token against the store
2026-09-28 08:24:52 +02:00
swarm-ca.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
swarm-container-resolver.nix
fix( #3363 ): swarm containers write their own resolver file
2026-08-17 17:30:15 +02:00
swarm-controller.nix
swarm-bao: agent certificates issued by a store-generated agent CA
2026-09-27 22:59:27 +02:00
swarm-grafana.nix
host-modules: atomic_write_secret takes the value as an argument, not stdin
2026-09-26 21:50:03 +02:00
swarm-nats.nix
swarm-nats-auth: verify an agent's own token against the store
2026-09-28 08:24:52 +02:00
swarm-otel.nix
host-modules: atomic_write_secret takes the value as an argument, not stdin
2026-09-26 21:50:03 +02:00
swarm-peers-removed.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm-required-services.nix
nix: run the forge on one host per swarm (deploy.forgejo.enable)
2026-09-24 23:56:07 +02:00
swarm-secret-publisher.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
swarm-snapshot-store.nix
deploy: move the wireguard mesh out of the namespace hives read
2026-09-07 14:24:52 +02:00
swarm-ui.nix
nix: give the gateway, resolver and bridge their own enable
2026-09-19 13:53:10 +02:00
swarm-victorialogs.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
swarm-victoriametrics.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
swarm-wireguard.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
swarm.nix
swarm-nats-auth: verify an agent's own token against the store
2026-09-28 08:24:52 +02:00