Watch
0
0
Fork
You've already forked hyperhive
0
a swarm o agents, each in its own nspawn cage, gossiping over unix sockets. config changes flow as git commits, the operator approves them in a browser, every deploy is a tag. cyberpunk-themed dashboard included. 💜⚡
  • Rust 64%
  • Nix 22.3%
  • JavaScript 4.8%
  • TypeScript 4.4%
  • CSS 3%
  • Other 1.5%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas ba56bfe32e nix: split swarm-authelia into service and deploy-mode files
`swarm.authelia` (what the SSO provider is to every hive: ports, domain,
`url`, the OIDC client register, the published names and the bridge's
address) moves to nix/host-modules/swarm-authelia-service.nix. Everything
else -- the `deploy.authelia` options, the whole `config` block including
`containers.swarm-authelia`, and the helpers only they read -- stays in
nix/host-modules/swarm-authelia.nix, which default.nix now imports
alongside the new file.

Both halves read four `let` bindings. `cfg`, `swarmDomain` and `deployCfg`
are option reads, so each file binds them from `config`; the service file
has no `hyperhiveCfg`, so it spells the paths out, as
swarm-nats-service.nix does. `instance` and `unitName` are literals, not
options, so the service file carries its own copy of the two (`unit`'s
default reads `unitName`). `deployCfg` is in the service file only for
`bridgeUrl`'s default, which is moved as it is.

`hyperhiveDomain` had no reader and is dropped rather than carried into
either file.

A pure move: option paths, option definitions and config are unchanged
apart from three comments that pointed "above"/"below" across the new
file boundary and now name the file. Authelia's container toplevel, the
host toplevel (with `c0re.hyperhiveFlake` pinned, since the flake source
path lands in /etc/hyperhive/serve.json), the `swarm.authelia` and
`deploy.authelia` values and option set, and the eleven
module-eval checks that enable authelia evaluate to the same derivations
before and after.

Refs #3742
2026-10-01 10:25:19 +02:00
.forgejo/workflows ci: internal jobs skip on the public forge instead of waiting for a hive-ci runner 2026-09-28 19:28:23 +02:00
branding swarm-ui: make it installable as a PWA 2026-09-12 11:30:20 +02:00
claude-plugins claude-plugins: format the swarm-logs skill with nix fmt 2026-09-17 15:17:33 +02:00
docs remove the create_repo agent tool 2026-10-01 09:04:17 +02:00
frontend Make agent creation swarm-only and refuse a name placed on another hive 2026-09-29 15:47:40 +02:00
hive-agent hive-agent: export ACP-reported cost and context fill over OTLP 2026-09-30 22:24:06 +02:00
hive-agent-mcp remove the create_repo agent tool 2026-10-01 09:04:17 +02:00
hive-agent-sock hive-c0re: render the new agent option paths into generated agent flakes 2026-09-17 20:19:30 +02:00
hive-bash-mcp hive-bash-mcp: drop the redundant output-path line from status's description 2026-09-13 15:56:10 +02:00
hive-c0re remove the create_repo agent tool 2026-10-01 09:04:17 +02:00
hive-core-agent-sock remove the create_repo agent tool 2026-10-01 09:04:17 +02:00
hive-forge hive-forge: bound the web-router client's connect and request waits 2026-09-29 09:17:47 +02:00
hive-forge-notify hive-forge-notify: a failed assigned-count poll leaves the rollup todo unchanged 2026-09-27 05:12:39 +02:00
hive-host-sock matrix: swarm-controller is the only minter 2026-09-30 00:46:46 +02:00
hive-jobq treefmt: apply prettier 2026-09-02 15:25:07 +02:00
hive-jobq-metrics move otel_http_client from swarm-queue-client into swarm-controller 2026-08-29 11:17:24 +02:00
hive-jobq-wire address review: move parse_states/filter_nodes_by_state to hive-jobq-wire, rename placeholder enums, trim core-mirroring framing 2026-08-16 16:59:54 +02:00
hive-log log: send records natively to journald, keep stdout off-unit 2026-09-21 15:52:57 +02:00
hive-matrix-mcp Drop the last references to the removed hive matrix login form 2026-09-29 13:54:18 +02:00
hive-metric docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
hive-priv hive-priv: remove the RestartMatrixDaemon command 2026-09-29 13:54:18 +02:00
hive-priv-sock hive-priv: remove the RestartMatrixDaemon command 2026-09-29 13:54:18 +02:00
hive-runtime hive-runtime: re-export ACP_API_KEY_ENV_ENV 2026-09-30 22:55:03 +02:00
hive-screen-mcp hive-screen-mcp: bound grim/wtype and VNC calls; hive-c0re: make messages match the code 2026-09-27 20:47:06 +02:00
hive-sh4re remove the create_repo agent tool 2026-10-01 09:04:17 +02:00
hive-sock-client remove the create_repo agent tool 2026-10-01 09:04:17 +02:00
hive-subagent-mcp hive-runtime: read the ACP provider key from bao 2026-09-30 22:55:03 +02:00
hive-types swarm-controller: refuse a new agent name the forge would reject 2026-09-24 15:16:32 +02:00
hivectl matrix: swarm-controller is the only minter 2026-09-30 00:46:46 +02:00
nix nix: split swarm-authelia into service and deploy-mode files 2026-10-01 10:25:19 +02:00
scripts check-issue-refs.sh: scan .ini files too; drop tracker tags from .vale.ini 2026-09-20 18:59:46 +02:00
swagger-ui-theme treefmt: apply prettier 2026-09-02 15:25:07 +02:00
swarm-authelia-bridge check-issue-refs: catch full forge issue URLs too, drop internal links from docs entirely 2026-09-09 21:15:28 +02:00
swarm-authelia-bridge-sock feat(swarm-authelia-bridge): report a heal as its own outcome 2026-08-23 19:00:41 +02:00
swarm-controller remove the create_repo agent tool 2026-10-01 09:04:17 +02:00
swarm-logs swarm-controller: read the queue client secret from the store, drop the file 2026-09-28 19:01:05 +02:00
swarm-matrix-client swarm-matrix-ctl: mint the swarm's own appservice registration 2026-09-25 08:31:01 +02:00
swarm-matrix-ctl matrix: swarm-controller is the only minter 2026-09-30 00:46:46 +02:00
swarm-nats-auth swarm-controller: re-issue agent certificates and re-mint queue secrets at half-life 2026-09-28 21:35:01 +02:00
swarm-queue-client hive-agent: read the per-agent queue secret from bao in process 2026-09-29 10:18:07 +02:00
swarm-secret-client hive-runtime: read the ACP provider key from bao 2026-09-30 22:55:03 +02:00
swarmctl Make agent creation swarm-only and refuse a name placed on another hive 2026-09-29 15:47:40 +02:00
.gitignore docs: address review — redundancy proof for Passive, wave-2 split, re-enable Contractions 2026-09-07 11:56:31 +02:00
.mailmap chore(#2165): add damocles@pr1ma + lexis@pr1ma mailmap entries 2026-07-04 13:50:16 +02:00
.prettierignore swarm-logs-cli.md: regenerate from the binary, prettierignore it 2026-09-17 01:02:14 +02:00
.prettierrc temp: add prettier configs 2026-07-02 23:33:11 +02:00
.vale.ini check-issue-refs.sh: scan .ini files too; drop tracker tags from .vale.ini 2026-09-20 18:59:46 +02:00
Cargo.lock hive-runtime: read the ACP provider key from bao 2026-09-30 22:55:03 +02:00
Cargo.toml hive-runtime: shared runtime crate with claude and acp backends 2026-09-29 22:29:36 +02:00
CLAUDE.md hive-runtime, hive-agent: model/effort picker for ACP agents from configOptions 2026-09-30 10:53:53 +02:00
clippy.toml swarm-logs: an agent's CLI for the swarm log store 2026-09-17 01:02:14 +02:00
flake.lock nix flake update 2026-10-01 05:01:18 +02:00
flake.nix nix: list nix/container-modules/ among the module trees 2026-09-29 19:51:46 +02:00
README.md hivectl, hive-c0re: remove dead matrix create-user/promote-user/reset-password 2026-09-29 13:13:59 +02:00

hyperhive

a swarm of claude-code agents, each in its own nspawn cage, gossiping over unix sockets. config changes flow as git commits, the operator approves them in a browser, every deploy is a tag. cyberpunk-themed dashboard included. 💜⚡

Claude code is great in one window, exponentielle across many — but only if you can keep the agents from stepping on each other, give them durable identity, and stop them from eating production. hyperhive is the substrate.

  • identity = unix socket
  • communication = sqlite-backed broker (send / recv / remind)
  • config = git (manager proposes, operator approves, deploys land as tagged commits)
  • blast radius = container
every hive (NixOS host, runs hive-c0re.service)
│
├── operator
│   ├── browser → :80 (hive-gateway)    dashboard + per-agent UIs
│   │                                   /agent/<name>/ → per-agent unix socket
│   └── CLI     → /run/hyperhive/host.sock   admin protocol
│
├── hive-c0re  (Rust daemon: lifecycle / broker / approvals /
│               auto-update / dashboard / sockets)
│
├── hive-gateway (optional)   nginx — proxies :80 → c0re dashboard + per-agent sockets
│
└── agent containers
    ├── h-ruth     manager (privileged MCP surface, approval gating)
    └── h-<name>   sub-agent (claude + MCP tools + per-agent web UI + unix socket)

one host per swarm (optional — connects hives; can be any hive, including
one that's also running the tree above)
│
├── hive-forge             Forgejo — swarm-wide singleton, per-agent accounts + config mirror
├── hive-matrix            tuwunel — swarm-wide singleton, Matrix homeserver + per-agent accounts
├── swarm-controller       cross-hive state: hive directory, agent roster, jobs
├── swarm-ui               swarm-wide SPA, served straight off the gateway (no own container)
├── swarm-authelia         SSO — one login gates swarm-ui + Grafana + more
├── swarm-nats             message queue (JetStream KV: hive-status, …)
├── swarm-otel             telemetry collector, sole holder of the upstream credential
├── swarm-victoriametrics  metrics store
├── swarm-victorialogs     log store
└── swarm-grafana          dashboards over the metrics/log stores, own OIDC login

→ website · → docs · → options reference

Depth lives in docs/ (rendered at hyperhive.darkest.space/docs/) — start at docs/README.md and pick the page matching your task rather than reading front to back.

Quick start

Minimal flake.nix for a host that runs hive-c0re:

{
  inputs = {
    nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";
    hyperhive.url = "git+https://forge.darkest.space/hyperhive/hyperhive";
    # Pin hyperhive to your own nixpkgs instead of the one it ships with
    # (see "Overriding nixpkgs" below) — recommended for most hosts:
    hyperhive.inputs.nixpkgs.follows = "nixpkgs";
  };

  outputs = { nixpkgs, hyperhive, ... }: {
    nixosConfigurations.my-host = nixpkgs.lib.nixosSystem {
      system = "x86_64-linux";
      modules = [
        hyperhive.nixosModules.default  # hive-c0re + hive-forge + hive-gateway in one import
        ({ ... }: {
          services.hyperhive.deploy.hive-controller.enable = true;
          # services.hyperhive.c0re.operatorPronouns = "they/them";  # default: "she/her"

          # ... rest of your host config
          system.stateVersion = "25.11";
        })
      ];
    };
  };
}

hive-c0re opens its admin socket + dashboard, auto-creates the manager container, and auto-rebuilds any container whose hyperhive rev goes stale. claude-code is unfree — hyperhive scopes the whitelist to itself, nothing for the operator to set.

Overriding nixpkgs

hyperhive pins its own nixpkgs so it builds standalone in CI. Add hyperhive.inputs.nixpkgs.follows = "nixpkgs" (as in the quick-start above) to build it against your host's nixpkgs instead — one less nixpkgs evaluation, no version drift from the rest of your system. Standard flake follows pattern; works as long as your channel is reasonably close to the nixos-26.05 hyperhive develops against. Drop it again if a much older/newer channel hits breakage hyperhive's CI doesn't catch.

For the full list of host and agent NixOS options see the options reference.

Operator CLI

hivectl is the operator-facing host CLI for ad-hoc administration that doesn't go through the broker (built alongside hive-c0re when the host module is enabled). Human matrix accounts come from SSO login, not hivectl.

A human's first SSO login to the forge makes their forge account, not hivectl; swarmctl forge make-admin <name> on the swarm-controller's host makes it a site admin.

Build / deploy

nix develop -c cargo check
nix flake check        # rust + nix + toml fmt + clippy

# deploy from a host config that imports hyperhive.nixosModules.default
nix flake update --update-input hyperhive
sudo nixos-rebuild switch --flake .#<host>