atlas
bc594a36ef
fix(hive-forge): give the SSO-source unit the same TLS trust as forgejo
...
Registering the OIDC login source makes an outbound HTTPS call - the CLI
fetches <issuer>/.well-known/openid-configuration to validate the
provider before writing the row. That URL is a swarm service name served
under the swarm CA, which the default system store has never heard of.
SSL_CERT_FILE was set on forgejo.service and not on
forgejo-sso-source.service, so the web service trusted the chain and the
registration one-shot did not. Same binary, same host, different unit.
The result was a 100% reproducible failure that no restart could fix:
nothing about restarting a unit gives it an environment variable it
never had. Every recorded run since the feature landed has failed with
x509: certificate signed by unknown authority.
The trust belongs to every process that makes the call, not to the
service that happens to be the obvious consumer.
2026-08-15 22:01:46 +02:00
..
hive-c0re
remove certFingerprint + HYPERHIVE_PEERS plumbing (hyperhive#3294)
2026-08-15 19:55:29 +02:00
hive-forge
fix(hive-forge): give the SSO-source unit the same TLS trust as forgejo
2026-08-15 22:01:46 +02:00
hive-gateway
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
lib
feat(nix): issue each hive's CA under a swarm root CA
2026-08-05 15:57:50 +02:00
default.nix
feat(3112): the swarm-nats container, fail-closed
2026-08-14 16:26:12 +02:00
hive-ci.nix
feat(nix): move the forge host options under services.hyperhive.swarm
2026-08-05 03:44:53 +02:00
hive-matrix.nix
swarm-controller: serve swarm-wide service quick links (hyperhive#3289)
2026-08-15 14:24:52 +02:00
hive-network.nix
docs(3191): the gateway's comments describe a host service, not a container
2026-08-12 12:20:28 +02:00
hive-priv.nix
fix( #2573 ): also add /etc/tmpfiles.d to hive-priv ReadWritePaths (same EROFS class)
2026-07-18 16:39:20 +02:00
hive-tls.nix
docs(3191): drop the migration history from the gateway comments
2026-08-12 13:26:58 +02:00
hyperhive.nix
refactor(nix): a hive's domain comes out of the swarm directory
2026-08-05 22:43:17 +02:00
local-defaults.nix
refactor(3202): all-local asserts the host's own /etc/hosts entries
2026-08-13 17:26:08 +02:00
otel.nix
docs(otel): validateConfigFile is a parser, not a wiring check
2026-08-15 12:13:48 +02:00
swarm-authelia.nix
feat(swarm-authelia): one machine client per hive in the roster
2026-08-15 14:26:05 +02:00
swarm-ca.nix
fix(nix): a missing swarm-services leaf must not kill the whole gateway
2026-08-06 00:30:22 +02:00
swarm-controller.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm-nats.nix
feat(swarm-authelia): let an oidc client say it is a machine client
2026-08-15 13:33:31 +02:00
swarm-peers-removed.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm-required-services.nix
refactor(nix): make all-local a deployment mode, not a default
2026-08-05 19:41:11 +02:00
swarm-snapshot-store.nix
refactor( #2862 ): keep the option at services.hyperhive.snapshotStore
2026-07-31 19:03:24 +02:00
swarm-ui.nix
swarm-controller: serve swarm-wide service quick links (hyperhive#3289)
2026-08-15 14:24:52 +02:00
swarm-wireguard.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm.nix
remove certFingerprint + HYPERHIVE_PEERS plumbing (hyperhive#3294)
2026-08-15 19:55:29 +02:00