hyperhive/swarm-matrix-minter
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas f778122f5a matrix: mint the appservice sender token in the matrix container
A swarm runs one homeserver and a homeserver has one appservice sender
account, so "mint it once" is a property of the thing being minted
rather than something a lock has to enforce. That is what makes this
account the one to move first: no trigger route, no controller change
and no agent list — a boot-time oneshot beside tuwunel is the whole
mechanism.

`swarm-matrix-minter` runs inside `containers.hive-matrix`, which
already holds the appservice token: the rendered registration is bound
in read-only because that is how tuwunel is handed it. What the
container lacked was an identity of its own, so this adds one — a leaf
from the store's CA with a grant of exactly one path, not the hive's
leaf, which reads every secret in the store.

Both ends of the credential ship here. The minter reads the path it
publishes to before it touches the homeserver, and returning on a
non-empty read IS the "only once"; `hive-c0re`'s `ensure_hive_user`
reads the same path, authenticating with the hive name already in
`HYPERHIVE_HIVE_NAME`. The existing mint-then-`M_USER_IN_USE`-login
ladder stays as the fallback for a store that is empty, unconfigured or
unreachable, which is every swarm deployed before this — so nothing
needs backfilling and nothing breaks if the rest of the sequence never
lands.

The credential is not an admin credential, and is not named like one.
It is the access token of the appservice registration's own
`sender_localpart` — `@hive:<server_name>`, an account the homeserver
creates for itself when it loads the registration. The store path is
`swarm/services/matrix/sender-token`, the host path is
`matrix/access-token`, and the homeserver no longer runs an
`admin_execute` promotion for that account at boot. Everything the hive
provisions with it — the Space, the chat room, their hierarchy and join
rules, the invites — rides on being the creator of those rooms at power
level 100, not on homeserver admin; there is no Synapse admin API here
to need, tuwunel has none.

Two operations do need an admin *sender* and therefore stop working:
`hivectl matrix promote-user` and `hivectl matrix reset-password`, both
`!admin …` messages into `#admins:<server>`, plus the password-reset
recovery path that an agent with a lost password file falls back to.
They are swarm-level operations and are left failing loudly rather than
served by an over-privileged token every other call site would also
carry. The sweep's own admin-rights check and self-repair go with them:
an account that is deliberately not an admin has nothing to check.

`ephemeral = false` stays, and hive root can still read the container's
filesystem. Accepted: what this buys is identity separation — no hive
*process* holds or reads the appservice token — not physical isolation.

Refs #4345
2026-09-20 22:07:16 +02:00
..
src matrix: mint the appservice sender token in the matrix container 2026-09-20 22:07:16 +02:00
Cargo.toml matrix: mint the appservice sender token in the matrix container 2026-09-20 22:07:16 +02:00
README.md matrix: mint the appservice sender token in the matrix container 2026-09-20 22:07:16 +02:00

swarm-matrix-minter

A boot-time oneshot that runs inside containers.hive-matrix, beside the homeserver, and puts the @hive: account's access token into the swarm's secret store under an identity of its own.

Why it lives in the matrix container

The credential it mints is authorised by the appservice as_token, and the container already holds that: nix/host-modules/hive-matrix.nix bind-mounts the rendered appservice registration into it read-only, because that is how tuwunel itself is handed the registration. Minting anywhere else would mean copying the as_token to a second holder — and the point of this component is that the hive stops being one.

It is not the swarm controller for the same reason, plus a structural one: a homeserver has exactly one @hive: account and a swarm runs one homeserver, so "mint it once" needs no lock, no lease and no trigger surface — it is a property of the thing being minted.

Idempotency

The store is the key, not the homeserver. A run reads swarm/services/matrix/hive-access-token first and returns without touching the homeserver when something is already there. Only an empty path reaches the mint ladder:

  1. POST /_matrix/client/v3/register with "type": "m.login.application_service" — one round trip, no UIAA.
  2. M_USER_IN_USE (the expected arm on a homeserver that has already loaded the registration, since the account is the appservice's own sender_localpart) → POST /_matrix/client/v3/login as the appservice, same pinned device_id, so the old device is replaced rather than duplicated.
  3. Write the result to the store.

A crash between the homeserver call and the store write is recoverable: the next run takes arm 2.

🩸 A secret is a path, never a value

Nothing here logs, prints or interpolates a token. The mint ladder's errors are built from the homeserver's status and its errcode, never its body, because a /login response body is an access token. The one identifier this binary logs is the store path it wrote.