atlas
78d8d69c7f
swarm-controller: mint each hive's matrix sender token
...
A hive whose homeserver runs on another host has no local
matrix-appservice-token, so hive-c0re's matrix sweep returned before
reaching the store read in ensure_hive_user: no @hive-<name>: token, no
Space, no chat room, no invites, and a sweep-health banner.
swarm-controller now mints @hive-<name>: with the swarm appservice
token for every hive in its directory, as a MintHiveSenderToken job
node queued by a five-minute pass, and stores it at
swarm/hives/<name>/matrix/sender-token, the same matrix::Credential
swarm-matrix-ctl writes there. It is keep-if-live, reusing agent_token's
classify/plan: a stored token whoami confirms as @hive-<name>: is left
alone, so only an absent or dead one is minted. agent_token's probe and
mint steps are lifted into probe_at/mint_at so both passes share them.
swarm-matrix-ctl mint still writes the path for its own hive when it is
empty. If both mint an empty path at once, one token is invalidated
(same pinned device); the next pass classifies it Revoked and re-mints.
hive-c0re's ensure_all no longer returns when there is no local
as_token. ensure_hive_user reads the store first on every sweep and
overwrites its token file when the store's token differs, keeps the
file when the store has none, mints with the local as_token only when
neither holds one, and fails with one error when there is nothing at
all. The decision is sender_source, unit-tested.
The controller's bao policy gains create/read/update on
swarm/hives/+/matrix/sender-token (`+`, since `*` is a glob only at the
end of a path), pinned in module-eval.
Refs #4427
2026-09-29 22:14:40 +02:00
..
hive-c0re
hive-priv: create agent socket dirs on start; drop hyperhive-agents.conf
2026-09-27 18:55:33 +02:00
hive-forge
nix: move the remaining service containers onto the swarm-container module
2026-09-29 20:17:28 +02:00
hive-gateway
hive-priv: create agent socket dirs on start; drop hyperhive-agents.conf
2026-09-27 18:55:33 +02:00
lib
lint: tighten atomic-write-secret.nix's header comment; fix vale contractions in persistence.md
2026-09-26 21:50:03 +02:00
swarm-grafana /dashboards
swarm-grafana: revert busiest-agents table, restore bargauges ( #4658 )
2026-09-28 11:52:33 +02:00
bao-bootstrap-policy.hcl
bao: disable the unused approle auth method, declaratively
2026-09-28 22:58:36 +02:00
default.nix
bao: OIDC login to the browser UI via authelia, as a metadata-only viewer
2026-09-28 19:56:38 +02:00
deploy.nix
swarm-controller: read the queue client secret from the store, drop the file
2026-09-28 19:01:05 +02:00
glue-bao-readers-policy-order.nix
swarm-bao: write every swarm-* grant as a bao granter, not with a 24h token
2026-09-27 22:57:46 +02:00
glue-bao-tls.nix
swarm-nats-auth: verify an agent's own token against the store
2026-09-28 08:24:52 +02:00
glue-bao-ui-oidc-client.nix
bao: OIDC login to the browser UI via authelia, as a metadata-only viewer
2026-09-28 19:56:38 +02:00
glue-controller-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-forge-oidc-client.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-grafana-oidc-client.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-matrix-bao-token.nix
host-modules: atomic_write_secret takes the value as an argument, not stdin
2026-09-26 21:50:03 +02:00
glue-matrix-ctl-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-nats-auth-bao-identity.nix
swarm-nats-auth: verify an agent's own token against the store
2026-09-28 08:24:52 +02:00
glue-nats-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-queue-agent-credential.nix
host-modules: atomic_write_secret takes the value as an argument, not stdin
2026-09-26 21:50:03 +02:00
glue-secret-publisher-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-services-issuer-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-swarm-bao-otel-oidc-client.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-swarm-otel-oidc-client.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
hive-ci.nix
nix: move the remaining service containers onto the swarm-container module
2026-09-29 20:17:28 +02:00
hive-matrix.nix
nix: move the remaining service containers onto the swarm-container module
2026-09-29 20:17:28 +02:00
hive-network.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
hive-priv.nix
hive-priv: create agent socket dirs on start; drop hyperhive-agents.conf
2026-09-27 18:55:33 +02:00
hive-tls.nix
bao: serve the browser UI to admins via a loopback-only listener
2026-09-28 19:31:02 +02:00
hyperhive.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
local-defaults.nix
swarm-controller: read the queue client secret from the store, drop the file
2026-09-28 19:01:05 +02:00
otel.nix
otel.nix: trim the StartLimit comment block to the load-bearing points
2026-09-23 17:22:51 +02:00
stylix-theme.nix
swarm-ui: apply the operator's stylix theme, same as the dashboard already does
2026-08-24 14:28:25 +02:00
swarm-authelia.nix
nix: move the remaining service containers onto the swarm-container module
2026-09-29 20:17:28 +02:00
swarm-bao.nix
swarm-controller: mint each hive's matrix sender token
2026-09-29 22:14:40 +02:00
swarm-ca.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
swarm-controller.nix
swarm-controller: read the queue client secret from the store, drop the file
2026-09-28 19:01:05 +02:00
swarm-grafana.nix
swarm-grafana: provision alert rules for forge reconcile + swarm terminal publish failures
2026-09-29 22:12:28 +02:00
swarm-nats.nix
nix: move the remaining service containers onto the swarm-container module
2026-09-29 20:17:28 +02:00
swarm-otel.nix
nix: move the remaining service containers onto the swarm-container module
2026-09-29 20:17:28 +02:00
swarm-peers-removed.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm-required-services.nix
nix: run the forge on one host per swarm (deploy.forgejo.enable)
2026-09-24 23:56:07 +02:00
swarm-secret-publisher.nix
bao: OIDC login to the browser UI via authelia, as a metadata-only viewer
2026-09-28 19:56:38 +02:00
swarm-snapshot-store.nix
deploy: move the wireguard mesh out of the namespace hives read
2026-09-07 14:24:52 +02:00
swarm-ui.nix
nix: give the gateway, resolver and bridge their own enable
2026-09-19 13:53:10 +02:00
swarm-victorialogs.nix
nix: move the remaining service containers onto the swarm-container module
2026-09-29 20:17:28 +02:00
swarm-victoriametrics.nix
nix: move the in-container modules to nix/container-modules/
2026-09-29 19:51:46 +02:00
swarm-wireguard.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
swarm.nix
bao: serve the browser UI to admins via a loopback-only listener
2026-09-28 19:31:02 +02:00