Watch
0
0
Fork
You've already forked hyperhive
0
a swarm o agents, each in its own nspawn cage, gossiping over unix sockets. config changes flow as git commits, the operator approves them in a browser, every deploy is a tag. cyberpunk-themed dashboard included. 💜⚡
  • Rust 64%
  • Nix 22.3%
  • JavaScript 4.8%
  • TypeScript 4.4%
  • CSS 3%
  • Other 1.5%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas b14ff2796c
Some checks were skipped
public bin cache / build + push to preem:grid (push) Has been skipped
bao: OIDC login to the browser UI via authelia, as a metadata-only viewer
The bao UI at bao-ui.<swarm> took a raw store token and nothing else.
It now offers an OIDC tab: authelia's `admins` group logs in and lands
on `swarm-operator-viewer`, which is list+read on `secret/metadata/*`
and nothing under `secret/data/` or `sys/`.

- authelia registers an interactive client `swarm-bao-ui`
  (glue-bao-ui-oidc-client.nix) with redirect
  `https://bao-ui.<swarm>/ui/vault/auth/oidc/oidc/callback`; the secret
  publisher carries its secret to
  `secret/swarm/services/swarm-bao-ui/oidc/client`.
- `swarm-bao-granter-role` (bootstrap token) enables the `oidc` auth
  mount with listing visibility `unauth`, asked before attempted like
  cert/approle; `bao-bootstrap-policy.hcl` gains `sys/auth/oidc`.
- The granter's policy gains `auth/oidc/config`, `auth/oidc/role/swarm-*`
  and read on that one secret leaf. It still holds no `sys/auth`.
- New granting unit `swarm-bao-operator-viewer-policy` writes the viewer
  policy, and once the granter may configure `auth/oidc/config` (checked
  through `sys/capabilities-self`), writes the mount's config from the
  published secret and the role binding `groups=admins` to the viewer.
  Before the bootstrap step re-runs it writes the policy, logs the step
  and exits 0.

Route (a) per mara on #4775: enabling the auth method stays a
bootstrap-token step, re-run once on the live store.

module-eval pins the viewer policy's single metadata stanza, that the
granter's policy has no sys/auth path, the oidc enable in the bootstrap
unit, the exit-0 path, the config/role contents, and the client
registration + publish.
2026-09-28 19:56:38 +02:00
.forgejo/workflows ci: internal jobs skip on the public forge instead of waiting for a hive-ci runner 2026-09-28 19:28:23 +02:00
branding swarm-ui: make it installable as a PWA 2026-09-12 11:30:20 +02:00
claude-plugins claude-plugins: format the swarm-logs skill with nix fmt 2026-09-17 15:17:33 +02:00
docs bao: OIDC login to the browser UI via authelia, as a metadata-only viewer 2026-09-28 19:56:38 +02:00
frontend agent ui: add a clickable new-session menu entry 2026-09-28 13:53:58 +02:00
hive-agent swarm-controller: read the queue client secret from the store, drop the file 2026-09-28 19:01:05 +02:00
hive-agent-mcp docs+comments: say what changed instead of tagging the tracker item 2026-09-21 22:43:16 +02:00
hive-agent-sock hive-c0re: render the new agent option paths into generated agent flakes 2026-09-17 20:19:30 +02:00
hive-bash-mcp hive-bash-mcp: drop the redundant output-path line from status's description 2026-09-13 15:56:10 +02:00
hive-c0re hive-screen-mcp: bound grim/wtype and VNC calls; hive-c0re: make messages match the code 2026-09-27 20:47:06 +02:00
hive-core-agent-sock remove the get_host_journal MCP tool and its capability 2026-09-21 19:31:45 +02:00
hive-forge agents: pull the forge token from bao; drop tea-login 2026-09-24 17:48:53 +02:00
hive-forge-notify hive-forge-notify: a failed assigned-count poll leaves the rollup todo unchanged 2026-09-27 05:12:39 +02:00
hive-host-sock hivectl: drop forge create-user; SSO makes a human's forge account 2026-09-25 08:29:56 +02:00
hive-jobq treefmt: apply prettier 2026-09-02 15:25:07 +02:00
hive-jobq-metrics move otel_http_client from swarm-queue-client into swarm-controller 2026-08-29 11:17:24 +02:00
hive-jobq-wire address review: move parse_states/filter_nodes_by_state to hive-jobq-wire, rename placeholder enums, trim core-mirroring framing 2026-08-16 16:59:54 +02:00
hive-log log: send records natively to journald, keep stdout off-unit 2026-09-21 15:52:57 +02:00
hive-matrix-mcp hive-matrix-mcp: read the main account's token from the store too 2026-09-25 08:31:01 +02:00
hive-metric docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
hive-priv hive-priv: create agent socket dirs on start; drop hyperhive-agents.conf 2026-09-27 18:55:33 +02:00
hive-priv-sock hive-priv: create agent socket dirs on start; drop hyperhive-agents.conf 2026-09-27 18:55:33 +02:00
hive-screen-mcp hive-screen-mcp: bound grim/wtype and VNC calls; hive-c0re: make messages match the code 2026-09-27 20:47:06 +02:00
hive-sh4re topology: drop the parent field and the hierarchy it fed 2026-09-21 22:08:47 +02:00
hive-sock-client hive-sock-client, web proxy, HTTP clients: bound connect and response waits 2026-09-27 03:46:53 +02:00
hive-subagent-mcp subagent: make interrupt cancel a goal run, not just its turn 2026-09-23 23:14:13 +02:00
hive-types swarm-controller: refuse a new agent name the forge would reject 2026-09-24 15:16:32 +02:00
hivectl hive-c0re: stop minting agents' matrix accounts 2026-09-25 08:31:01 +02:00
nix bao: OIDC login to the browser UI via authelia, as a metadata-only viewer 2026-09-28 19:56:38 +02:00
scripts check-issue-refs.sh: scan .ini files too; drop tracker tags from .vale.ini 2026-09-20 18:59:46 +02:00
swagger-ui-theme treefmt: apply prettier 2026-09-02 15:25:07 +02:00
swarm-authelia-bridge check-issue-refs: catch full forge issue URLs too, drop internal links from docs entirely 2026-09-09 21:15:28 +02:00
swarm-authelia-bridge-sock feat(swarm-authelia-bridge): report a heal as its own outcome 2026-08-23 19:00:41 +02:00
swarm-controller swarm-controller: read the queue client secret from the store, drop the file 2026-09-28 19:01:05 +02:00
swarm-logs swarm-controller: read the queue client secret from the store, drop the file 2026-09-28 19:01:05 +02:00
swarm-matrix-client swarm-matrix-ctl: mint the swarm's own appservice registration 2026-09-25 08:31:01 +02:00
swarm-matrix-ctl swarm-matrix-ctl: mint the swarm's own appservice registration 2026-09-25 08:31:01 +02:00
swarm-nats-auth swarm: let an agent publish its own icon 2026-09-28 13:47:37 +02:00
swarm-queue-client swarm-controller: read the queue client secret from the store, drop the file 2026-09-28 19:01:05 +02:00
swarm-secret-client swarm-controller: read the queue client secret from the store, drop the file 2026-09-28 19:01:05 +02:00
swarmctl swarm-queue-client: one agent-token spelling, and no hive in AgentCredential 2026-09-28 08:24:52 +02:00
.gitignore docs: address review — redundancy proof for Passive, wave-2 split, re-enable Contractions 2026-09-07 11:56:31 +02:00
.mailmap chore(#2165): add damocles@pr1ma + lexis@pr1ma mailmap entries 2026-07-04 13:50:16 +02:00
.prettierignore swarm-logs-cli.md: regenerate from the binary, prettierignore it 2026-09-17 01:02:14 +02:00
.prettierrc temp: add prettier configs 2026-07-02 23:33:11 +02:00
.vale.ini check-issue-refs.sh: scan .ini files too; drop tracker tags from .vale.ini 2026-09-20 18:59:46 +02:00
Cargo.lock swarm-nats-auth: verify an agent's own token against the store 2026-09-28 08:24:52 +02:00
Cargo.toml swarm-nats-auth: verify an agent's own token against the store 2026-09-28 08:24:52 +02:00
CLAUDE.md log: send records natively to journald, keep stdout off-unit 2026-09-21 15:52:57 +02:00
clippy.toml swarm-logs: an agent's CLI for the swarm log store 2026-09-17 01:02:14 +02:00
flake.lock nix flake update 2026-09-27 14:33:24 +02:00
flake.nix nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00
README.md nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable 2026-09-26 01:19:49 +02:00

hyperhive

a swarm of claude-code agents, each in its own nspawn cage, gossiping over unix sockets. config changes flow as git commits, the operator approves them in a browser, every deploy is a tag. cyberpunk-themed dashboard included. 💜⚡

Claude code is great in one window, exponentielle across many — but only if you can keep the agents from stepping on each other, give them durable identity, and stop them from eating production. hyperhive is the substrate.

  • identity = unix socket
  • communication = sqlite-backed broker (send / recv / remind)
  • config = git (manager proposes, operator approves, deploys land as tagged commits)
  • blast radius = container
every hive (NixOS host, runs hive-c0re.service)
│
├── operator
│   ├── browser → :80 (hive-gateway)    dashboard + per-agent UIs
│   │                                   /agent/<name>/ → per-agent unix socket
│   └── CLI     → /run/hyperhive/host.sock   admin protocol
│
├── hive-c0re  (Rust daemon: lifecycle / broker / approvals /
│               auto-update / dashboard / sockets)
│
├── hive-gateway (optional)   nginx — proxies :80 → c0re dashboard + per-agent sockets
│
└── agent containers
    ├── h-ruth     manager (privileged MCP surface, approval gating)
    └── h-<name>   sub-agent (claude + MCP tools + per-agent web UI + unix socket)

one host per swarm (optional — connects hives; can be any hive, including
one that's also running the tree above)
│
├── hive-forge             Forgejo — swarm-wide singleton, per-agent accounts + config mirror
├── hive-matrix            tuwunel — swarm-wide singleton, Matrix homeserver + per-agent accounts
├── swarm-controller       cross-hive state: hive directory, agent roster, jobs
├── swarm-ui               swarm-wide SPA, served straight off the gateway (no own container)
├── swarm-authelia         SSO — one login gates swarm-ui + Grafana + more
├── swarm-nats             message queue (JetStream KV: hive-status, …)
├── swarm-otel             telemetry collector, sole holder of the upstream credential
├── swarm-victoriametrics  metrics store
├── swarm-victorialogs     log store
└── swarm-grafana          dashboards over the metrics/log stores, own OIDC login

→ website · → docs · → options reference

Depth lives in docs/ (rendered at hyperhive.darkest.space/docs/) — start at docs/README.md and pick the page matching your task rather than reading front to back.

Quick start

Minimal flake.nix for a host that runs hive-c0re:

{
  inputs = {
    nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";
    hyperhive.url = "git+https://forge.darkest.space/hyperhive/hyperhive";
    # Pin hyperhive to your own nixpkgs instead of the one it ships with
    # (see "Overriding nixpkgs" below) — recommended for most hosts:
    hyperhive.inputs.nixpkgs.follows = "nixpkgs";
  };

  outputs = { nixpkgs, hyperhive, ... }: {
    nixosConfigurations.my-host = nixpkgs.lib.nixosSystem {
      system = "x86_64-linux";
      modules = [
        hyperhive.nixosModules.default  # hive-c0re + hive-forge + hive-gateway in one import
        ({ ... }: {
          services.hyperhive.deploy.hive-controller.enable = true;
          # services.hyperhive.c0re.operatorPronouns = "they/them";  # default: "she/her"

          # ... rest of your host config
          system.stateVersion = "25.11";
        })
      ];
    };
  };
}

hive-c0re opens its admin socket + dashboard, auto-creates the manager container, and auto-rebuilds any container whose hyperhive rev goes stale. claude-code is unfree — hyperhive scopes the whitelist to itself, nothing for the operator to set.

Overriding nixpkgs

hyperhive pins its own nixpkgs so it builds standalone in CI. Add hyperhive.inputs.nixpkgs.follows = "nixpkgs" (as in the quick-start above) to build it against your host's nixpkgs instead — one less nixpkgs evaluation, no version drift from the rest of your system. Standard flake follows pattern; works as long as your channel is reasonably close to the nixos-26.05 hyperhive develops against. Drop it again if a much older/newer channel hits breakage hyperhive's CI doesn't catch.

For the full list of host and agent NixOS options see the options reference.

Operator CLI

hivectl is the operator-facing host CLI for ad-hoc administration that doesn't go through the broker (built alongside hive-c0re when the host module is enabled):

sudo hivectl matrix create-user mara                      # provisions a matrix user
sudo hivectl matrix create-user mara --password-stdin     # … reading one line from stdin

For a name that's a managed agent, hivectl persists the resulting token to that agent's state dir, the same as the boot sweep does. For a non-agent name (for example the operator's own matrix account), it prints the token to stdout and writes nothing.

A human's first SSO login to the forge makes their forge account, not hivectl; swarmctl forge make-admin <name> on the swarm-controller's host makes it a site admin.

Build / deploy

nix develop -c cargo check
nix flake check        # rust + nix + toml fmt + clippy

# deploy from a host config that imports hyperhive.nixosModules.default
nix flake update --update-input hyperhive
sudo nixos-rebuild switch --flake .#<host>