hyperhive/nix/host-modules
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas cb787997bd otel: the hive tier presents its own identity to the swarm collector
The receiving half authenticates per hive, so this half has to prove which
hive it is. It mints a token against the swarm's authelia with this hive's
client and posts to that hive's path on the collector's gateway name.

Holding a credential is what decides whether this tier authenticates —
`clientSecretFile` non-null — rather than a second switch that could
disagree with it. The default is the secret this host's own authelia
minted, which is right exactly when the IdP runs here; a hive that is not
that host names wherever the file landed, the same manual-copy shape the
identities option already documents as unsolved.

Two things that a diff will not explain:

`endpoint_params.audience` is not redundant with the client's registered
audience. Registering only makes an audience permissible; a token minted
without asking for one carries `aud: []` and every receiver refuses it,
with a config that reads correctly at both ends.

`client_secret_file` keeps the secret out of nix altogether — the
collector opens the file itself. It is a real key of this extension,
checked against the shipped binary with a deliberate typo rejected in the
same run, so "accepted" is distinguishable from "ignores everything". The
path comes from systemd's `CREDENTIALS_DIRECTORY`, so nothing hardcodes a
`/run/credentials` layout.

An assertion covers the one deployment where this can go wrong silently:
a host running both tiers with ingest authenticated and no credential to
present would 401 against a collector on the same machine.
2026-08-19 15:27:09 +02:00
..
hive-c0re fix(otel): let the SDK resolve hive-c0re's OTLP endpoint 2026-08-19 01:38:54 +02:00
hive-forge forge: pin issue search indexer to db, not bleve 2026-08-18 23:29:40 +02:00
hive-gateway docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
lib swarm-otel: authenticate ingest per hive, and stamp the hive from the receiver 2026-08-19 15:27:09 +02:00
default.nix feat(#3125): a swarm-tier OTEL collector, in its own container 2026-08-18 21:02:18 +02:00
hive-ci.nix feat(nix): move the forge host options under services.hyperhive.swarm 2026-08-05 03:44:53 +02:00
hive-matrix.nix feat(#3162): warn when a hive with an existing homeserver has not pinned serverName 2026-08-18 12:29:31 +02:00
hive-network.nix docs(network): drop the otel reasoning instead of restating it 2026-08-19 02:04:57 +02:00
hive-priv.nix fix(#2573): also add /etc/tmpfiles.d to hive-priv ReadWritePaths (same EROFS class) 2026-07-18 16:39:20 +02:00
hive-tls.nix fix(#3462): apply the name check in the unit that runs on the deploy 2026-08-18 21:54:38 +02:00
hyperhive.nix refactor(nix): a hive's domain comes out of the swarm directory 2026-08-05 22:43:17 +02:00
local-defaults.nix fix(#3343): move the all-local queue derivations into the deployment mode 2026-08-16 19:37:49 +02:00
otel.nix otel: the hive tier presents its own identity to the swarm collector 2026-08-19 15:27:09 +02:00
swarm-authelia.nix swarm-authelia: give each hive client an audience and JWT access tokens 2026-08-19 15:27:09 +02:00
swarm-ca.nix fix(nix): a missing swarm-services leaf must not kill the whole gateway 2026-08-06 00:30:22 +02:00
swarm-container-resolver.nix fix(#3363): swarm containers write their own resolver file 2026-08-17 17:30:15 +02:00
swarm-controller.nix swarm-ui: show the swarm's name as the page title and top-left brand 2026-08-18 18:34:56 +02:00
swarm-grafana.nix fix(#3471): keep Metrics Drilldown, which declarativePlugins had silently removed 2026-08-18 22:40:59 +02:00
swarm-nats.nix fix(#3363): give the queue's auth responder the hive CA 2026-08-17 19:57:44 +02:00
swarm-otel.nix swarm-otel: authenticate ingest per hive, and stamp the hive from the receiver 2026-08-19 15:27:09 +02:00
swarm-peers-removed.nix docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
swarm-required-services.nix feat(#3125): reshape the hive-to-swarm OTEL hop by domain 2026-08-18 21:02:18 +02:00
swarm-snapshot-store.nix refactor(#2862): keep the option at services.hyperhive.snapshotStore 2026-07-31 19:03:24 +02:00
swarm-ui.nix feat(#3255): expose the controller's webhook endpoint through the swarm vhost 2026-08-18 12:28:09 +02:00
swarm-victoriametrics.nix fix(#3363): swarm containers write their own resolver file 2026-08-17 17:30:15 +02:00
swarm-wireguard.nix docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
swarm.nix fix(#3462): the swarm-services leaf never covered grafana, metrics or otel 2026-08-18 21:54:38 +02:00