atlas
a7dbe732fb
hive-ci: give the runner daemon the hive CA it needs for TLS
...
NODE_EXTRA_CA_CERTS beside it is Node's and additive. gitea-runner is Go,
whose trust store is replacing: it reads SSL_CERT_FILE and trusts only
what that names. So the container trusted the hive CA for its Node
actions and never for the daemon itself.
The daemon then fails startup with x509 unknown authority the moment it
reaches a TLS endpoint, crash-loops on Restart=on-failure, and no job is
picked up -- every pull request just sits at Waiting to run.
Not claimed as the whole cause of that outage: which address the daemon
holds is a separate question. The trust gap is real under every
explanation, and adding a CA to one unit cannot break a working path.
2026-08-26 18:30:24 +02:00
..
hive-c0re
swarm-otel: collect only the units the swarm's services declare
2026-08-24 22:05:45 +02:00
hive-forge
forge, matrix: SSO is not optional
2026-08-24 23:06:25 +02:00
hive-gateway
swarm-otel: collect only the units the swarm's services declare
2026-08-24 22:05:45 +02:00
lib
fix( #3527 ): a missing source must report as zero, not as empty
2026-08-19 20:27:00 +02:00
swarm-grafana /dashboards
feat(swarm-grafana): provision an authelia dashboard
2026-08-24 15:59:28 +02:00
default.nix
feat(swarm-victorialogs): a log store for the swarm
2026-08-24 16:36:18 +02:00
hive-ci.nix
hive-ci: give the runner daemon the hive CA it needs for TLS
2026-08-26 18:30:24 +02:00
hive-matrix.nix
forge, matrix: SSO is not optional
2026-08-24 23:06:25 +02:00
hive-network.nix
docs(network): drop the otel reasoning instead of restating it
2026-08-19 02:04:57 +02:00
hive-priv.nix
fix( #2573 ): also add /etc/tmpfiles.d to hive-priv ReadWritePaths (same EROFS class)
2026-07-18 16:39:20 +02:00
hive-tls.nix
fix( #3462 ): apply the name check in the unit that runs on the deploy
2026-08-18 21:54:38 +02:00
hyperhive.nix
refactor(nix): a hive's domain comes out of the swarm directory
2026-08-05 22:43:17 +02:00
local-defaults.nix
fix( #3343 ): move the all-local queue derivations into the deployment mode
2026-08-16 19:37:49 +02:00
otel.nix
feat( #3554 ): let a hive-owned service declare a scrape target
2026-08-23 22:45:56 +02:00
stylix-theme.nix
swarm-ui: apply the operator's stylix theme, same as the dashboard already does
2026-08-24 14:28:25 +02:00
swarm-authelia.nix
swarm-authelia: collect the journal of the unit that actually runs
2026-08-26 01:06:50 +02:00
swarm-ca.nix
swarm-otel: collect only the units the swarm's services declare
2026-08-24 22:05:45 +02:00
swarm-container-resolver.nix
fix( #3363 ): swarm containers write their own resolver file
2026-08-17 17:30:15 +02:00
swarm-controller.nix
swarm-otel: collect only the units the swarm's services declare
2026-08-24 22:05:45 +02:00
swarm-grafana.nix
swarm-otel: collect only the units the swarm's services declare
2026-08-24 22:05:45 +02:00
swarm-nats.nix
swarm-nats: manual callout needs all four keys, not two
2026-08-24 23:06:59 +02:00
swarm-otel.nix
swarm-otel: collect only the units the swarm's services declare
2026-08-24 22:05:45 +02:00
swarm-peers-removed.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm-required-services.nix
feat(swarm): start the log store with the other required services
2026-08-24 17:00:38 +02:00
swarm-snapshot-store.nix
refactor( #2862 ): keep the option at services.hyperhive.snapshotStore
2026-07-31 19:03:24 +02:00
swarm-ui.nix
swarm-ui: swap colors.css via a plain nginx location, not a package-copy derivation
2026-08-24 14:28:25 +02:00
swarm-victorialogs.nix
swarm-otel: collect only the units the swarm's services declare
2026-08-24 22:05:45 +02:00
swarm-victoriametrics.nix
swarm-otel: collect only the units the swarm's services declare
2026-08-24 22:05:45 +02:00
swarm-wireguard.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm.nix
swarm: publish an authenticated gateway vhost for VictoriaLogs
2026-08-24 18:43:26 +02:00