hyperhive/nix/host-modules
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas bb62bf1aa9 swarm: guard hive names where the roster is declared, and reserve the cert subjects
The two hive-name guards lived in swarm-otel.nix, inside its
`config = lib.mkIf (… && deployCfg.swarm-otel.enable)`. A swarm running the
secret store and the controller but no collector therefore had no hive-name
check at all, while the names were still composed into OIDC client ids, bao
policies and cert-auth roles exactly the same way. They move to swarm.nix,
which declares `swarm.hives` and is unconditional. swarm-otel keeps the
assertion that its own entry is still in the shared list — that one is about
this module's stake in a file it no longer controls.

The equality guard also takes the store's cert-auth subjects now. Cert auth
trusts the CA, so `allowed_common_names` is the whole of what narrows a role
to one identity, and the same CA signs every hive's leaf with the hive's name
as its CN. A hive named after a role's subject presents a certificate that
role accepts, which for the controller is write access to every hive's
credentials and policies.

A list rather than the one string, because the next role added beside it
widens what a hive name must not collide with, and because the subject is an
option an operator sets — a literal deny entry covers the default and nothing
else.

Four module-eval cases, two of them controls. The fixture overrides the
subject to `ctl` on purpose: the default contains `swarm`, which the substring
guard catches whatever the new arm does, so a fixture using it could not tell
the two apart. The controls are that a legal roster trips neither guard, and
that all three fixtures really do have the collector disabled — without the
second, every case would pass while testing the arrangement they exist to
rule out.
2026-09-11 22:28:44 +02:00
..
hive-c0re hive-c0re: one binding for /run/hyperhive's mode 2026-09-11 19:35:36 +02:00
hive-forge forge: move the forgejo package to deploy — slice 10 complete 2026-09-07 20:46:38 +02:00
hive-gateway docs: matrix gateway vhost defaults to chat.<swarm-domain>, not matrix.<domain> 2026-09-07 16:53:22 +02:00
lib swarm: extract the name guards, so the module just says what is forbidden 2026-08-31 18:50:15 +02:00
swarm-grafana/dashboards grafana: show which sources are shipping, not just that the store is up 2026-09-08 00:43:23 +02:00
default.nix bao: mint the controller's leaf, and point the controller at it 2026-09-07 22:24:42 +02:00
deploy.nix forge: move the forgejo package to deploy — slice 10 complete 2026-09-07 20:46:38 +02:00
glue-bao-tls.nix swarm-bao-tls: drop the unreachable CN fallback 2026-09-10 00:25:07 +02:00
glue-controller-bao-identity.nix swarm-controller: hand the daemon the authority hives are issued from 2026-09-10 00:25:07 +02:00
glue-matrix-bao-token.nix deploy: split the homeserver's host decisions out of swarm.matrix 2026-09-07 14:24:52 +02:00
hive-ci.nix deploy: split the forge's host decisions out of swarm.forge 2026-09-07 14:24:52 +02:00
hive-matrix.nix swarm: move the matrix packages to deploy, where their enable already lives 2026-09-07 20:46:37 +02:00
hive-network.nix docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
hive-priv.nix docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
hive-tls.nix docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
hyperhive.nix docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
local-defaults.nix bao: write the swarm controller's policy from inside the store 2026-09-07 18:43:09 +02:00
otel.nix otel: forward each agent container's journal to its hive collector 2026-09-11 09:03:49 +02:00
stylix-theme.nix swarm-ui: apply the operator's stylix theme, same as the dashboard already does 2026-08-24 14:28:25 +02:00
swarm-authelia.nix swarm: move both authelia packages to deploy 2026-09-07 20:46:38 +02:00
swarm-bao.nix swarm-bao: create the KV mount the controller writes credentials through 2026-09-11 00:16:46 +02:00
swarm-ca.nix swarm-ca: state the store-is-world-readable rule once, not three times 2026-09-02 09:03:35 +02:00
swarm-container-resolver.nix fix(#3363): swarm containers write their own resolver file 2026-08-17 17:30:15 +02:00
swarm-controller.nix swarm-controller: hand the daemon the authority hives are issued from 2026-09-10 00:25:07 +02:00
swarm-grafana.nix swarm-grafana: grafana requires SSO, so the login form goes unconditionally 2026-09-11 18:23:51 +02:00
swarm-nats.nix swarm-nats, swarm-victorialogs: correct two comments that describe a topology we do not have 2026-09-10 23:18:40 +02:00
swarm-otel.nix swarm: guard hive names where the roster is declared, and reserve the cert subjects 2026-09-11 22:28:44 +02:00
swarm-peers-removed.nix docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
swarm-required-services.nix deploy: rename enableAllLocalDefaults to deploy.singleHostSwarm 2026-08-30 20:12:16 +02:00
swarm-snapshot-store.nix deploy: move the wireguard mesh out of the namespace hives read 2026-09-07 14:24:52 +02:00
swarm-ui.nix swarm: move the controller's two packages to deploy 2026-09-07 20:46:38 +02:00
swarm-victorialogs.nix swarm-nats, swarm-victorialogs: correct two comments that describe a topology we do not have 2026-09-10 23:18:40 +02:00
swarm-victoriametrics.nix swarm: move both metric stores' package to deploy, and cover their shims 2026-09-07 20:46:38 +02:00
swarm-wireguard.nix deploy: move the wireguard mesh out of the namespace hives read 2026-09-07 14:24:52 +02:00
swarm.nix swarm: guard hive names where the roster is declared, and reserve the cert subjects 2026-09-11 22:28:44 +02:00