hyperhive/docs
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas b8157cb08e swarm: read the agent queue credential out of the store onto the hive host
The publisher on the authelia host has been writing
`secret/swarm/hives/<hive>/queue/agent` — the OIDC client secret agent
containers present to the swarm queue, plus the client id it belongs to —
and nothing read it. This is the reader: a oneshot `swarm-bao-queue-agent`
that logs in with the host's certificate and lands the two fields as two
files under `deploy.hive-controller.queue.agentCredentialDir`, the secret
`0600` and the client id `0644`.

Two files rather than one because that is the consumer's shape:
`swarm_queue_client::QueueConfig::from_env` takes the secret as a path and
the client id as a value, so the split here is what keeps the next slice
from parsing anything.

Same shape as the store's first reader, `glue-matrix-bao-token.nix` — a
cert login that fails loudly under `Restart=on-failure` because every state
it fails on is one a retry fixes, then reads that degrade quietly because no
retry turns "no value there" into a value. Unlike the matrix token there is
no local fallback and none is possible, so absent files mean this hive's
agents do not connect, which is the ordinary state of a swarm before the
publisher has run.

Nothing consumes the files yet and this unit is ordered `Before=` nothing.
The next slice bind-mounts them into agent containers through hive-c0re and
adds the ordering edge along with them.

Refs #3805
2026-09-12 21:05:52 +02:00
..
agent-lifecycle docs: drop the operator-schedule-target aside from approvals.md 2026-09-11 23:32:45 +02:00
crates check-issue-refs: catch full forge issue URLs too, drop internal links from docs entirely 2026-09-09 21:15:28 +02:00
getting-started docs/setup: use the emphasis form treefmt's prettier normalises to 2026-09-11 19:30:17 +02:00
integrations docs: name options by the path an operator can set, not by cfg.* 2026-09-11 13:32:24 +02:00
networking swarm: give agent containers their own queue principal 2026-09-12 10:33:06 +02:00
process docs: name options by the path an operator can set, not by cfg.* 2026-09-11 13:32:24 +02:00
scheduler docs/observability: hive→swarm ingest auth shipped, stop calling it planned 2026-09-11 18:11:19 +02:00
swarm swarm: read the agent queue credential out of the store onto the hive host 2026-09-12 21:05:52 +02:00
tools docs: regenerate forge-cli.md for the --limit/--tail opt-in swap 2026-09-11 19:13:30 +02:00
trust-boundary swarm: say the read policy names the hive it is written for 2026-09-12 11:41:01 +02:00
turn-loop hivectl, docs: choom is not root-only, and set-limits takes no agent name 2026-09-11 19:11:13 +02:00
web-ui job_queue: fix dangling rustdoc intra-doc link left by strum conversion 2026-09-12 00:06:31 +02:00
README.md check-issue-refs: catch full forge issue URLs too, drop internal links from docs entirely 2026-09-09 21:15:28 +02:00

hyperhive docs

Depth reference for hyperhive — the substrate, not the pitch (that's the top-level README / website). Every page here stands alone; pick the one matching your task rather than reading top to bottom. For the autogenerated NixOS options reference (every services.hyperhive.* / hyperhive.* option, host and agent), see the options site instead — this tree is prose, that one's generated straight from the module declarations.

Getting started

  • Bringing a fresh hive online?getting-started/setup.md (first-run hivectl bootstrap).
  • What does the dashboard look like, and how do I use it?web-ui/ — the operator-facing starting point; its own sub-pages (shape, dashboard, agent, css-vars, terminal-rendering) go deeper into implementation.
  • What tools does an agent (or the operator) have available?tools/hivectl (yours) plus every agent's MCP tool surface (bash, forge, lifecycle, matrix, scheduling).

Agent lifecycle

Trust boundary & security

Accounts & integrations

  • How do per-agent forge accounts work? What does forge_notify poll, and how does it format wake messages?integrations/forge.md (the hive's own Forgejo); tools/forge.md for the hive-forge CLI verbs agents actually call.
  • How does the matrix-tuwunel container work? Multiple accounts per agent?integrations/matrix.md (the homeserver); tools/matrix.md for the MCP tool surface and hyperhive.matrixAccounts.
  • How do I give an agent a GitHub account (gh + git push)? how's the PAT injected?integrations/github.md (operator content up top; the gh/git-push + notification-poller mechanics are in a collapsed "Implementation" section at the bottom).
  • What's /knowledge? How does the hive-wide knowledge repo sync, and how do I contribute a document?integrations/knowledge.md.
  • What does hivectl do? Provisioning, gateway users, container shells?tools/hivectl.md (the curated guide); tools/hivectl-cli.md for the exhaustive, autogenerated flag reference.

Networking & swarms

  • What nginx vhosts does the gateway serve? How does matrix discovery work?networking/gateway.md.
  • How does DNS resolution work in agent containers? What's the bridge network for?networking/network.md.
  • How do I connect two hives into a swarm?swarm/ (peer hives, TLS trust).
  • Where do agent snapshots go? How does the swarm's btrfs receive endpoint authenticate a pushing hive?networking/snapshot-store.md.

Scheduler, CI, observability

  • what's the job queue, as a general idea (not hive-c0re specifics)?scheduler/jobq.md — operator-facing, no implementation detail.
  • How does the rebuild queue work? What are the concrete step kinds, queue sources, scheduler internals?scheduler/coordinator.md.
  • How does the CI runner work? What's the autoregistration flow?scheduler/ci.md.
  • How do I export Claude Code metrics (tokens, cost, tool calls) to Prometheus/Grafana?scheduler/observability.md.

Crate reference

  • What does a specific Rust crate do, on its own terms?crates/ — every workspace crate's own README.md, one level up from source; the crate itself is still the source of truth, this is just a walkable mirror.

Process & conventions