atlas
d337fec565
feat(3167): authelia gates the swarm UI on an operators group
...
default_policy = one_factor means 'any authenticated user', which is
authentication and not authorisation. The swarm UI is operator-only and
agents are getting authelia accounts of their own, so a session alone
would be enough to open it the day that lands - the vhost's auth_request
would be a check nobody fails.
Adds an access_control rule for the UI's domain requiring
subject = group:operators, present only when the UI is enabled. The
group name is a constant beside the rule: it is also what an operator
types into 'swarmctl user add --group', and a configurable name is one
more way for the rule and the account to disagree silently.
2026-08-12 17:31:30 +02:00
..
hive-c0re
fix(3191): let hive-c0re write the gateway conf dir under strict sandboxing
2026-08-12 16:39:58 +02:00
hive-forge
fix(3149): pass the oauth flags as an array, and verify the source exists
2026-08-12 15:04:18 +02:00
hive-gateway
docs(3191): drop the migration history from the gateway comments
2026-08-12 13:26:58 +02:00
lib
feat(nix): issue each hive's CA under a swarm root CA
2026-08-05 15:57:50 +02:00
default.nix
feat(3167): options + certificate name for the swarm UI
2026-08-12 17:29:13 +02:00
hive-ci.nix
feat(nix): move the forge host options under services.hyperhive.swarm
2026-08-05 03:44:53 +02:00
hive-matrix.nix
docs(3191): drop the migration history from the gateway comments
2026-08-12 13:26:58 +02:00
hive-network.nix
docs(3191): the gateway's comments describe a host service, not a container
2026-08-12 12:20:28 +02:00
hive-priv.nix
fix( #2573 ): also add /etc/tmpfiles.d to hive-priv ReadWritePaths (same EROFS class)
2026-07-18 16:39:20 +02:00
hive-tls.nix
docs(3191): drop the migration history from the gateway comments
2026-08-12 13:26:58 +02:00
hyperhive.nix
refactor(nix): a hive's domain comes out of the swarm directory
2026-08-05 22:43:17 +02:00
local-defaults.nix
feat(3089): all-local asserts the swarm controller
2026-08-11 23:50:19 +02:00
otel.nix
refactor: nix/host-modules + nix/agent-modules layout, update doc paths
2026-07-13 22:05:49 +02:00
swarm-authelia.nix
feat(3167): authelia gates the swarm UI on an operators group
2026-08-12 17:31:30 +02:00
swarm-ca.nix
fix(nix): a missing swarm-services leaf must not kill the whole gateway
2026-08-06 00:30:22 +02:00
swarm-controller.nix
docs(3191): the gateway's comments describe a host service, not a container
2026-08-12 12:20:28 +02:00
swarm-peers-removed.nix
refactor(nix): swarm.peers becomes swarm.hives, a directory of every hive
2026-08-05 20:44:16 +02:00
swarm-required-services.nix
refactor(nix): make all-local a deployment mode, not a default
2026-08-05 19:41:11 +02:00
swarm-snapshot-store.nix
refactor( #2862 ): keep the option at services.hyperhive.snapshotStore
2026-07-31 19:03:24 +02:00
swarm-ui.nix
feat(3167): options + certificate name for the swarm UI
2026-08-12 17:29:13 +02:00
swarm-wireguard.nix
refactor(nix): swarm.peers becomes swarm.hives, a directory of every hive
2026-08-05 20:44:16 +02:00
swarm.nix
feat(3167): options + certificate name for the swarm UI
2026-08-12 17:29:13 +02:00