hyperhive/nix/host-modules
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas b8157cb08e swarm: read the agent queue credential out of the store onto the hive host
The publisher on the authelia host has been writing
`secret/swarm/hives/<hive>/queue/agent` — the OIDC client secret agent
containers present to the swarm queue, plus the client id it belongs to —
and nothing read it. This is the reader: a oneshot `swarm-bao-queue-agent`
that logs in with the host's certificate and lands the two fields as two
files under `deploy.hive-controller.queue.agentCredentialDir`, the secret
`0600` and the client id `0644`.

Two files rather than one because that is the consumer's shape:
`swarm_queue_client::QueueConfig::from_env` takes the secret as a path and
the client id as a value, so the split here is what keeps the next slice
from parsing anything.

Same shape as the store's first reader, `glue-matrix-bao-token.nix` — a
cert login that fails loudly under `Restart=on-failure` because every state
it fails on is one a retry fixes, then reads that degrade quietly because no
retry turns "no value there" into a value. Unlike the matrix token there is
no local fallback and none is possible, so absent files mean this hive's
agents do not connect, which is the ordinary state of a swarm before the
publisher has run.

Nothing consumes the files yet and this unit is ordered `Before=` nothing.
The next slice bind-mounts them into agent containers through hive-c0re and
adds the ordering edge along with them.

Refs #3805
2026-09-12 21:05:52 +02:00
..
hive-c0re hive-c0re: one binding for /run/hyperhive's mode 2026-09-11 19:35:36 +02:00
hive-forge forge: move the forgejo package to deploy — slice 10 complete 2026-09-07 20:46:38 +02:00
hive-gateway docs: matrix gateway vhost defaults to chat.<swarm-domain>, not matrix.<domain> 2026-09-07 16:53:22 +02:00
lib swarm: extract the name guards, so the module just says what is forbidden 2026-08-31 18:50:15 +02:00
swarm-grafana/dashboards grafana: switch the CLAUDE.md-size panel from a snapshot bar to a time series 2026-09-12 10:34:57 +02:00
default.nix swarm: read the agent queue credential out of the store onto the hive host 2026-09-12 21:05:52 +02:00
deploy.nix forge: move the forgejo package to deploy — slice 10 complete 2026-09-07 20:46:38 +02:00
glue-bao-tls.nix swarm: publish minted OIDC client secrets into the swarm store 2026-09-12 11:22:33 +02:00
glue-controller-bao-identity.nix swarm-controller: hand the daemon the authority hives are issued from 2026-09-10 00:25:07 +02:00
glue-matrix-bao-token.nix swarm: put the matrix registration token where the reader is granted 2026-09-12 19:46:04 +02:00
glue-queue-agent-credential.nix swarm: read the agent queue credential out of the store onto the hive host 2026-09-12 21:05:52 +02:00
glue-secret-publisher-bao-identity.nix swarm: publish minted OIDC client secrets into the swarm store 2026-09-12 11:22:33 +02:00
hive-ci.nix deploy: split the forge's host decisions out of swarm.forge 2026-09-07 14:24:52 +02:00
hive-matrix.nix swarm: move the matrix packages to deploy, where their enable already lives 2026-09-07 20:46:37 +02:00
hive-network.nix docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
hive-priv.nix docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
hive-tls.nix docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
hyperhive.nix docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
local-defaults.nix bao: write the swarm controller's policy from inside the store 2026-09-07 18:43:09 +02:00
otel.nix otel: scrape each collector's own loss counters 2026-09-12 10:34:06 +02:00
stylix-theme.nix swarm-ui: apply the operator's stylix theme, same as the dashboard already does 2026-08-24 14:28:25 +02:00
swarm-authelia.nix swarm: name the agent client after its hive, not after "agent" 2026-09-12 10:33:06 +02:00
swarm-bao.nix swarm-bao: write the secret publisher's policy and cert-auth role 2026-09-12 10:56:50 +02:00
swarm-ca.nix swarm-ca: state the store-is-world-readable rule once, not three times 2026-09-02 09:03:35 +02:00
swarm-container-resolver.nix fix(#3363): swarm containers write their own resolver file 2026-08-17 17:30:15 +02:00
swarm-controller.nix swarm-controller: hand the daemon the authority hives are issued from 2026-09-10 00:25:07 +02:00
swarm-grafana.nix swarm-grafana: grafana requires SSO, so the login form goes unconditionally 2026-09-11 18:23:51 +02:00
swarm-nats.nix swarm: name the agent client after its hive, not after "agent" 2026-09-12 10:33:06 +02:00
swarm-otel.nix hive-c0re: name an agent container after its machine, not "nixos" 2026-09-12 18:19:18 +02:00
swarm-peers-removed.nix docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
swarm-required-services.nix deploy: rename enableAllLocalDefaults to deploy.singleHostSwarm 2026-08-30 20:12:16 +02:00
swarm-secret-publisher.nix swarm: log in to bao before reading or writing a secret 2026-09-12 12:27:33 +02:00
swarm-snapshot-store.nix deploy: move the wireguard mesh out of the namespace hives read 2026-09-07 14:24:52 +02:00
swarm-ui.nix swarm: move the controller's two packages to deploy 2026-09-07 20:46:38 +02:00
swarm-victorialogs.nix swarm-nats, swarm-victorialogs: correct two comments that describe a topology we do not have 2026-09-10 23:18:40 +02:00
swarm-victoriametrics.nix swarm: move both metric stores' package to deploy, and cover their shims 2026-09-07 20:46:38 +02:00
swarm-wireguard.nix deploy: move the wireguard mesh out of the namespace hives read 2026-09-07 14:24:52 +02:00
swarm.nix swarm-bao, swarm: give the secret publisher its own subject, reserved like the controller's 2026-09-12 10:56:50 +02:00