hyperhive/docs
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas a39399f037 swarm-logs: an agent's CLI for the swarm log store
An agent can reach VictoriaLogs only through the gateway, and since the
machine query route landed the way to read it has been to hand-roll a
client_credentials token request and a curl, per query. This is the CLI
that closes that: `swarm-logs query '<LogsQL>'`, matched log lines on
stdout, so the answer pipes into grep like any other command's.

Built to the plan posted on the tracker thread: own crate, own
docs/tools reference generated off the clap tree, `query` as the one
verb, and the JSON error body surfaced on a non-200 rather than
swallowed. No `tail`: streaming is a different endpoint with a different
response shape, and folding it in here would be a fatter scope than the
ask.

Minting the token is NOT implemented here — swarm-queue-client already
owns the client_credentials request, its error type and its CA handling,
and a token-endpoint fix has to be findable in one place. What this crate
adds is the agent-shaped half: the client id arrives as a *file* beside
the secret, so nothing outside nix/agent-modules/queue.nix spells
`hive-<name>-agent` twice. That is the same problem hive-agent's
swarm_queue module solves, and swarm-logs/src/auth.rs is its `decide`
restated over this binary's inputs.

⚠️ The plan named one thing to verify empirically before calling the auth
settled: whether authelia's bearer policy for the logs vhost accepts the
agent client's audience. Measured from inside a container: it does not.
The client minted a token fine but with `aud: []` and `scp: []`, asking
for the logs URL as an audience answered `invalid_target`, and presenting
the audience-less token to the gateway answered a bare 401. So
swarm-authelia.nix's agentClients gains `authelia.bearer.authz` and the
query URL as a second audience — authelia authorises a bearer token by
the URL being requested, and that URL is now one binding read by three
places rather than three spellings of one address.

The URL reaches an agent the same way its queue coordinates do: computed
on the host (a container cannot derive a gateway address), forwarded by
hive_c0re::meta into the container's option set, and consumed by a new
agent module that installs the binary *wrapped* with its coordinates —
the shape swarm-controller.nix installs swarmctl in. Gated on the queue
credential as well as on the URL: a binary that can only answer 401 is
worse than no binary, because an agent reads a 401 as "no logs", which is
the exact confusion the store's machine route was added to end.
2026-09-17 01:02:14 +02:00
..
agent-lifecycle refactor(hive-c0re): drop the request_init_config tool and InitConfig approval 2026-09-14 19:03:44 +02:00
crates check-issue-refs: catch full forge issue URLs too, drop internal links from docs entirely 2026-09-09 21:15:28 +02:00
getting-started refactor(hive-c0re): drop the request_init_config tool and InitConfig approval 2026-09-14 19:03:44 +02:00
integrations matrix: publish the appservice token from the swarm, not just read it 2026-09-15 20:57:49 +02:00
networking swarm: give agent containers their own queue principal 2026-09-12 10:33:06 +02:00
process refactor(hive-c0re): drop the request_init_config tool and InitConfig approval 2026-09-14 19:03:44 +02:00
scheduler ops: address argus review findings on PR #4433 2026-09-16 00:07:02 +02:00
swarm docs/swarm/credentials.md: restore the new-vs-existing progressive-enhancement split 2026-09-17 00:02:00 +02:00
tools swarm-logs: an agent's CLI for the swarm log store 2026-09-17 01:02:14 +02:00
trust-boundary swarm-otel: deliver the OIDC client secret through the secret store 2026-09-14 00:58:58 +02:00
turn-loop permissions: give the built-in tool list one home, next to ToolGroup 2026-09-15 17:40:27 +02:00
web-ui refactor(hive-c0re): drop the request_init_config tool and InitConfig approval 2026-09-14 19:03:44 +02:00
README.md docs/swarm/credentials.md: reword prose to pass vale 2026-09-16 22:41:23 +02:00

hyperhive docs

Depth reference for hyperhive — the substrate, not the pitch (that's the top-level README / website). Every page here stands alone; pick the one matching your task rather than reading top to bottom. For the autogenerated NixOS options reference (every services.hyperhive.* / hyperhive.* option, host and agent), see the options site instead — this tree is prose, that one's generated straight from the module declarations.

Getting started

  • Bringing a fresh hive online?getting-started/setup.md (first-run hivectl bootstrap).
  • What does the dashboard look like, and how do I use it?web-ui/ — the operator-facing starting point; its own sub-pages (shape, dashboard, agent, css-vars, terminal-rendering) go deeper into implementation.
  • What tools does an agent (or the operator) have available?tools/hivectl (yours) plus every agent's MCP tool surface (bash, forge, lifecycle, matrix, scheduling).

Agent lifecycle

Trust boundary & security

Accounts & integrations

  • How do per-agent forge accounts work? What does forge_notify poll, and how does it format wake messages?integrations/forge.md (the hive's own Forgejo); tools/forge.md for the hive-forge CLI verbs agents actually call.
  • How does the matrix-tuwunel container work? Multiple accounts per agent?integrations/matrix.md (the homeserver); tools/matrix.md for the MCP tool surface and hyperhive.matrixAccounts.
  • How do I give an agent a GitHub account (gh + git push)? how's the PAT injected?integrations/github.md (operator content up top; the gh/git-push + notification-poller mechanics are in a collapsed "Implementation" section at the bottom).
  • What's /knowledge? How does the hive-wide knowledge repo sync, and how do I contribute a document?integrations/knowledge.md.
  • What does hivectl do? Provisioning, gateway users, container shells?tools/hivectl.md (the curated guide); tools/hivectl-cli.md for the exhaustive, autogenerated flag reference.

Networking & swarms

  • What nginx vhosts does the gateway serve? How does matrix discovery work?networking/gateway.md.
  • How does DNS resolution work in agent containers? What's the bridge network for?networking/network.md.
  • How do I connect two hives into a swarm?swarm/ (peer hives, TLS trust).
  • Where do agent snapshots go? How does the swarm's btrfs receive endpoint authenticate a pushing hive?networking/snapshot-store.md.
  • Who mints each credential, who reads it, and how does it rotate — and where's that shape headed?swarm/credentials.md (current state, target state, and the progressive-enhancement rule); swarm/secrets.md for where each file lives today.

Scheduler, CI, observability

  • what's the job queue, as a general idea (not hive-c0re specifics)?scheduler/jobq.md — operator-facing, no implementation detail.
  • How does the rebuild queue work? What are the concrete step kinds, queue sources, scheduler internals?scheduler/coordinator.md.
  • How does the CI runner work? What's the autoregistration flow?scheduler/ci.md.
  • How do I export Claude Code metrics (tokens, cost, tool calls) to Prometheus/Grafana?scheduler/observability.md.

Crate reference

  • What does a specific Rust crate do, on its own terms?crates/ — every workspace crate's own README.md, one level up from source; the crate itself is still the source of truth, this is just a walkable mirror.

Process & conventions