Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/nix/module-eval
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 9bad58d86d swarm-nats-auth: verify an agent's own token against the store
An `auth_token` spelled `swarm-agent.<agent>.<secret>` is no longer sent
to introspection. The responder reads `swarm/agents/<agent>/queue` with
an identity of its own, checks that the stored object names the same
agent, compares the secret in constant time, and grants the subjects
`--agent-token-publish-subject` lists with `{agent}` expanded. Every
other outcome denies: a malformed token, no store identity, nothing
stored, a failed or slow lookup, a different secret. A token without
the prefix takes the OIDC path unchanged.

The journal's `auth request` line names such a caller `agent:<agent>`;
the hive-shared credential keeps `hive-<h>-agent`.

The new principal: a `swarm-nats-auth` cert-auth role and policy with
read on `secret/data/swarm/agents/+/queue` alone, a leaf signed by the
store's PKI glue, and `glue-nats-auth-bao-identity.nix` pairing the two.
The copy unit delivers the identity into the queue's container, and an
absent leaf is delivered empty so the responder still starts and only
agent tokens are refused.

The policy and role are written by `swarm-bao-nats-auth-policy`, logged in
as the bao granter: both names fall under its `swarm-*` globs, so the
deploy writes them with no operator step. module-eval counts it among the
granting units, so every generic granting-unit case covers it.

The secret compare uses `subtle`, already in the lock file through the
TLS stack; no workspace crate offered one directly.
2026-09-28 08:24:52 +02:00
..
agent-forge-bao.nix module-eval: pin the agent forge-token fetch and tea-login's removal 2026-09-24 17:48:53 +02:00
agent-icon.nix nix: split module-eval into per-subsystem checks 2026-09-20 04:25:54 +02:00
agent-matrix.nix hive-matrix-mcp: read the main account's token from the store too 2026-09-25 08:31:01 +02:00
agent-memory.nix nix: split module-eval into per-subsystem checks 2026-09-20 04:25:54 +02:00
agent-otel.nix module-eval: assert the severity table once, not once per tier 2026-09-20 14:23:56 +02:00
agent-plugins.nix nix: split module-eval into per-subsystem checks 2026-09-20 04:25:54 +02:00
agent-queue-bao.nix agent: fetch this agent's own swarm-queue credential from the store 2026-09-21 20:44:52 +02:00
agent-user.nix hive-priv: create agent socket dirs on start; drop hyperhive-agents.conf 2026-09-27 18:55:33 +02:00
bao-basics.nix swarm-bao: agent certificates issued by a store-generated agent CA 2026-09-27 22:59:27 +02:00
bao-controller.nix swarm-bao: agent certificates issued by a store-generated agent CA 2026-09-27 22:59:27 +02:00
bao-grants.nix swarm-nats-auth: verify an agent's own token against the store 2026-09-28 08:24:52 +02:00
bao-matrix-reader.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
bao-otel-collector.nix swarm-bao: stop linking the container's journal onto the host 2026-09-25 04:02:08 +02:00
core-toggle.nix module-eval: read the services-leaf narrowing off a forge host 2026-09-26 01:39:22 +02:00
forge-placement.nix hive-forge: a first authelia login creates the forge account 2026-09-25 08:29:56 +02:00
grafana.nix swarm-bao: stamp collector's service.name as "bao" 2026-09-25 08:30:25 +02:00
hive-otel.nix swarm-bao: give the store's collector an explicit self-telemetry port 2026-09-23 18:04:33 +02:00
hive-tls.nix swarm-bao: write every swarm-* grant as a bao granter, not with a 24h token 2026-09-27 22:57:46 +02:00
journald-severity.nix module-eval: assert the severity table once, not once per tier 2026-09-20 14:23:56 +02:00
lib.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
matrix-core.nix nix: split module-eval into per-subsystem checks 2026-09-20 04:25:54 +02:00
name-guards.nix swarm-bao: write every swarm-* grant as a bao granter, not with a 24h token 2026-09-27 22:57:46 +02:00
nats-authelia.nix swarm-nats-auth: verify an agent's own token against the store 2026-09-28 08:24:52 +02:00
nats-tls.nix swarm-bao: write every swarm-* grant as a bao granter, not with a 24h token 2026-09-27 22:57:46 +02:00
secret-publisher.nix nix: the store's own collector scrapes its metrics listener 2026-09-21 17:19:52 +02:00
swarm-otel-core.nix swarm-bao: write every swarm-* grant as a bao granter, not with a 24h token 2026-09-27 22:57:46 +02:00
swarm-otel-identity.nix swarm-bao: refuse a remote reader that named seven of the eight leaves 2026-09-23 10:11:42 +02:00
swarm-services-switch.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00