hyperhive/nix/host-modules
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 97cde357e5 nix: derive hive identities and the token endpoint from the swarm, not this host
Two swarm-wide facts were being read off this machine's deploy set, so the
answer differed between two hosts of one swarm:

  - `swarm.authelia.oidc.hiveIdentities` defaulted to `deploy.nats.enable`,
    so whether a hive gets an identity at all depended on whether the IdP
    host happened to also run the queue. It is on by default now: a swarm's
    hives have identities, and the clients are inert until used.

  - `swarm.statusPublish.tokenEndpoint` defaulted through `queueLocal`
    (`deploy.nats.enable && deploy.authelia.enable`), so a hive that was not
    the swarm host had no token endpoint even when the swarm's IdP was
    reachable and named. It follows `swarm.authelia.url` now — the same
    derivation `swarm-controller.nix`'s own `queue.tokenEndpoint` already
    uses, which is correct for a remote provider.

`deploy.nix:1-30` is what makes this a rule rather than a preference:
`swarm.*` is "identical on every host, byte for byte" and `deploy.*` is
"necessarily different on every host". A swarm value derived from a deploy
value cannot satisfy both.

The all-or-nothing status-publish assertion follows: the token endpoint is
no longer one of the coordinates that says this hive publishes — every hive
in a swarm with an IdP has one — so the two per-host coordinates are what
must agree, and they now require the endpoint rather than being counted
beside it.

`queueLocal` itself stays for the three remaining host-local addresses
(`natsUrl`, `clientSecretFile`, `agentNatsUrl`): each of those is a
`deploy.*` value that genuinely differs per host.

Closes #4048
2026-09-19 14:31:19 +02:00
..
hive-c0re nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
hive-forge nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
hive-gateway docs(gateway): describe nginx as per-host, not a deployment-wide singleton 2026-09-19 13:58:10 +02:00
lib swarm: extract the name guards, so the module just says what is forbidden 2026-08-31 18:50:15 +02:00
swarm-grafana/dashboards swarm-grafana: distinct subagents by agent, over time 2026-09-18 09:38:49 +02:00
default.nix swarm-otel: deliver the OIDC client secret through the secret store 2026-09-14 00:58:58 +02:00
deploy.nix swarm-controller: make socketPath readOnly instead of asserting it 2026-09-17 19:27:30 +02:00
glue-bao-tls.nix swarm: publish minted OIDC client secrets into the swarm store 2026-09-12 11:22:33 +02:00
glue-controller-bao-identity.nix swarm-controller: hand the daemon the authority hives are issued from 2026-09-10 00:25:07 +02:00
glue-grafana-oidc-client.nix swarm-grafana: deliver the OIDC client secret through the secret store 2026-09-13 19:57:28 +02:00
glue-matrix-bao-token.nix matrix: remove the registration token 2026-09-15 19:58:10 +02:00
glue-queue-agent-credential.nix matrix: remove the registration token 2026-09-15 19:58:10 +02:00
glue-secret-publisher-bao-identity.nix swarm: publish minted OIDC client secrets into the swarm store 2026-09-12 11:22:33 +02:00
glue-swarm-otel-oidc-client.nix swarm-otel: deliver the OIDC client secret through the secret store 2026-09-14 00:58:58 +02:00
hive-ci.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
hive-matrix.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
hive-network.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
hive-priv.nix docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
hive-tls.nix docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
hyperhive.nix docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
local-defaults.nix bao: write the swarm controller's policy from inside the store 2026-09-07 18:43:09 +02:00
otel.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
stylix-theme.nix swarm-ui: apply the operator's stylix theme, same as the dashboard already does 2026-08-24 14:28:25 +02:00
swarm-authelia.nix nix: derive hive identities and the token endpoint from the swarm, not this host 2026-09-19 14:31:19 +02:00
swarm-bao.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
swarm-ca.nix swarm-ca: state the store-is-world-readable rule once, not three times 2026-09-02 09:03:35 +02:00
swarm-container-resolver.nix fix(#3363): swarm containers write their own resolver file 2026-08-17 17:30:15 +02:00
swarm-controller.nix nix: drop the central-toggle conjunct from four compound gates 2026-09-19 10:48:12 +02:00
swarm-grafana.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
swarm-nats.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
swarm-otel.nix nix: derive hive identities and the token endpoint from the swarm, not this host 2026-09-19 14:31:19 +02:00
swarm-peers-removed.nix docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
swarm-required-services.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
swarm-secret-publisher.nix matrix: publish the appservice token from the swarm, not just read it 2026-09-15 20:57:49 +02:00
swarm-snapshot-store.nix deploy: move the wireguard mesh out of the namespace hives read 2026-09-07 14:24:52 +02:00
swarm-ui.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
swarm-victorialogs.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
swarm-victoriametrics.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
swarm-wireguard.nix deploy: move the wireguard mesh out of the namespace hives read 2026-09-07 14:24:52 +02:00
swarm.nix nix: derive hive identities and the token endpoint from the swarm, not this host 2026-09-19 14:31:19 +02:00