atlas
d212125b48
fix( #3391 ): introspect authelia by name instead of loopback
...
A loopback literal encodes 'authelia is in my netns' at the call site,
and authelia's OIDC endpoints are https-only in effect: reached directly
they answer 400, because the forwarded headers nginx injects for every
other consumer are what let it determine its own issuer. Going by name
deletes the need for those headers rather than reproducing them, and
converges on the URL swarm-nats-auth already uses.
Depends on the CA trust added for the same container in #3407 -- without
it this swaps a 400 for an UnknownIssuer.
The null-url assertion joins the module's existing list: interpolating a
null would surface as a nix coercion error several files from its cause.
2026-08-17 20:02:15 +02:00
..
hive-c0re
feat(swarm): wire a hive's queue coordinates for status publishing
2026-08-16 13:14:03 +02:00
hive-forge
fix: let the secret-delivery oneshots outlive their own bounded wait
2026-08-16 21:45:33 +02:00
hive-gateway
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
lib
docs: trim the trustBundle comment under the 30-line lint
2026-08-17 19:57:44 +02:00
default.nix
feat( #3265 ): swarm metrics UI as a Grafana container
2026-08-16 22:27:05 +02:00
hive-ci.nix
feat(nix): move the forge host options under services.hyperhive.swarm
2026-08-05 03:44:53 +02:00
hive-matrix.nix
fix: let the secret-delivery oneshots outlive their own bounded wait
2026-08-16 21:45:33 +02:00
hive-network.nix
docs(3191): the gateway's comments describe a host service, not a container
2026-08-12 12:20:28 +02:00
hive-priv.nix
fix( #2573 ): also add /etc/tmpfiles.d to hive-priv ReadWritePaths (same EROFS class)
2026-07-18 16:39:20 +02:00
hive-tls.nix
fix( #3349 ): do not define a controller env key on hives with no controller
2026-08-16 20:55:39 +02:00
hyperhive.nix
refactor(nix): a hive's domain comes out of the swarm directory
2026-08-05 22:43:17 +02:00
local-defaults.nix
fix( #3343 ): move the all-local queue derivations into the deployment mode
2026-08-16 19:37:49 +02:00
otel.nix
docs( #3265 ): observability.md still said the endpoint was required
2026-08-16 22:27:05 +02:00
swarm-authelia.nix
fix( #3391 ): introspect authelia by name instead of loopback
2026-08-17 20:02:15 +02:00
swarm-ca.nix
fix(nix): a missing swarm-services leaf must not kill the whole gateway
2026-08-06 00:30:22 +02:00
swarm-container-resolver.nix
fix( #3363 ): swarm containers write their own resolver file
2026-08-17 17:30:15 +02:00
swarm-controller.nix
docs: trim the reload rationale to the live constraint
2026-08-17 19:25:27 +02:00
swarm-grafana.nix
fix( #3363 ): swarm containers write their own resolver file
2026-08-17 17:30:15 +02:00
swarm-nats.nix
fix( #3363 ): give the queue's auth responder the hive CA
2026-08-17 19:57:44 +02:00
swarm-peers-removed.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm-required-services.nix
swarm-required-services: trim otel.enable comment per review
2026-08-17 19:36:49 +02:00
swarm-snapshot-store.nix
refactor( #2862 ): keep the option at services.hyperhive.snapshotStore
2026-07-31 19:03:24 +02:00
swarm-ui.nix
swarm-controller: serve swarm-wide service quick links (hyperhive#3289)
2026-08-15 14:24:52 +02:00
swarm-victoriametrics.nix
fix( #3363 ): swarm containers write their own resolver file
2026-08-17 17:30:15 +02:00
swarm-wireguard.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm.nix
feat(swarm): wire a hive's queue coordinates for status publishing
2026-08-16 13:14:03 +02:00