atlas
8caf688ee4
swarm: revoke an agent's queue credential when it is declared destroyed
...
A per-agent queue credential is minted at agent creation and nothing has
ever removed it. An agent declared destroyed loses its container and
keeps its credential: a bearer secret recovered from a snapshot or a
stale capture still authenticates as that agent, so the set of usable
credentials only grows.
Delete the path the mint published, on the one transition that ends an
agent's life. It mirrors step 3 of `mint_and_verify` and no other step:
the leaf, the ACL document and the cert role are what a hive uses to
collect an agent's secrets and are re-minted on every run of the mint.
Every version, not the newest. The mint rewrites the path when the
principal it names needs correcting, so KV v2's plain delete would leave
the identical secret readable at ?version=N. That is a separately-ACL'd
path, hence the second stanza in the controller's grant -- `delete` on
metadata discloses nothing, and `update` on the data path already lets
this principal destroy any agent credential's usability.
The destroy is not blocked by a failed revocation: the declaration is
already published and refusing the call would leave an operator with an
agent they cannot tear down. The failure is logged at error instead,
naming the agent, since a silent orphan is the fault being removed.
2026-09-28 23:46:17 +02:00
..
hive-c0re
hive-priv: create agent socket dirs on start; drop hyperhive-agents.conf
2026-09-27 18:55:33 +02:00
hive-forge
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
hive-gateway
hive-priv: create agent socket dirs on start; drop hyperhive-agents.conf
2026-09-27 18:55:33 +02:00
lib
lint: tighten atomic-write-secret.nix's header comment; fix vale contractions in persistence.md
2026-09-26 21:50:03 +02:00
swarm-grafana /dashboards
swarm-grafana: revert busiest-agents table, restore bargauges ( #4658 )
2026-09-28 11:52:33 +02:00
bao-bootstrap-policy.hcl
bao: disable the unused approle auth method, declaratively
2026-09-28 22:58:36 +02:00
default.nix
bao: OIDC login to the browser UI via authelia, as a metadata-only viewer
2026-09-28 19:56:38 +02:00
deploy.nix
swarm-controller: read the queue client secret from the store, drop the file
2026-09-28 19:01:05 +02:00
glue-bao-readers-policy-order.nix
swarm-bao: write every swarm-* grant as a bao granter, not with a 24h token
2026-09-27 22:57:46 +02:00
glue-bao-tls.nix
swarm-nats-auth: verify an agent's own token against the store
2026-09-28 08:24:52 +02:00
glue-bao-ui-oidc-client.nix
bao: OIDC login to the browser UI via authelia, as a metadata-only viewer
2026-09-28 19:56:38 +02:00
glue-controller-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-forge-oidc-client.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-grafana-oidc-client.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-matrix-bao-token.nix
host-modules: atomic_write_secret takes the value as an argument, not stdin
2026-09-26 21:50:03 +02:00
glue-matrix-ctl-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-nats-auth-bao-identity.nix
swarm-nats-auth: verify an agent's own token against the store
2026-09-28 08:24:52 +02:00
glue-nats-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-queue-agent-credential.nix
host-modules: atomic_write_secret takes the value as an argument, not stdin
2026-09-26 21:50:03 +02:00
glue-secret-publisher-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-services-issuer-bao-identity.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-swarm-bao-otel-oidc-client.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
glue-swarm-otel-oidc-client.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
hive-ci.nix
nix: run the forge on one host per swarm (deploy.forgejo.enable)
2026-09-24 23:56:07 +02:00
hive-matrix.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
hive-network.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
hive-priv.nix
hive-priv: create agent socket dirs on start; drop hyperhive-agents.conf
2026-09-27 18:55:33 +02:00
hive-tls.nix
bao: serve the browser UI to admins via a loopback-only listener
2026-09-28 19:31:02 +02:00
hyperhive.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
local-defaults.nix
swarm-controller: read the queue client secret from the store, drop the file
2026-09-28 19:01:05 +02:00
otel.nix
otel.nix: trim the StartLimit comment block to the load-bearing points
2026-09-23 17:22:51 +02:00
stylix-theme.nix
swarm-ui: apply the operator's stylix theme, same as the dashboard already does
2026-08-24 14:28:25 +02:00
swarm-authelia.nix
bao: serve the browser UI to admins via a loopback-only listener
2026-09-28 19:31:02 +02:00
swarm-bao.nix
swarm: revoke an agent's queue credential when it is declared destroyed
2026-09-28 23:46:17 +02:00
swarm-ca.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
swarm-container-resolver.nix
fix( #3363 ): swarm containers write their own resolver file
2026-08-17 17:30:15 +02:00
swarm-controller.nix
swarm-controller: read the queue client secret from the store, drop the file
2026-09-28 19:01:05 +02:00
swarm-grafana.nix
host-modules: atomic_write_secret takes the value as an argument, not stdin
2026-09-26 21:50:03 +02:00
swarm-nats.nix
swarm: let an agent publish its own icon
2026-09-28 13:47:37 +02:00
swarm-otel.nix
host-modules: atomic_write_secret takes the value as an argument, not stdin
2026-09-26 21:50:03 +02:00
swarm-peers-removed.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm-required-services.nix
nix: run the forge on one host per swarm (deploy.forgejo.enable)
2026-09-24 23:56:07 +02:00
swarm-secret-publisher.nix
bao: OIDC login to the browser UI via authelia, as a metadata-only viewer
2026-09-28 19:56:38 +02:00
swarm-snapshot-store.nix
deploy: move the wireguard mesh out of the namespace hives read
2026-09-07 14:24:52 +02:00
swarm-ui.nix
nix: give the gateway, resolver and bridge their own enable
2026-09-19 13:53:10 +02:00
swarm-victorialogs.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
swarm-victoriametrics.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
swarm-wireguard.nix
nix: gate hive-c0re on deploy.hive-controller.enable, drop hyperhive.enable
2026-09-26 01:19:49 +02:00
swarm.nix
bao: serve the browser UI to admins via a loopback-only listener
2026-09-28 19:31:02 +02:00