hyperhive/hive-c0re/src
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas a39399f037 swarm-logs: an agent's CLI for the swarm log store
An agent can reach VictoriaLogs only through the gateway, and since the
machine query route landed the way to read it has been to hand-roll a
client_credentials token request and a curl, per query. This is the CLI
that closes that: `swarm-logs query '<LogsQL>'`, matched log lines on
stdout, so the answer pipes into grep like any other command's.

Built to the plan posted on the tracker thread: own crate, own
docs/tools reference generated off the clap tree, `query` as the one
verb, and the JSON error body surfaced on a non-200 rather than
swallowed. No `tail`: streaming is a different endpoint with a different
response shape, and folding it in here would be a fatter scope than the
ask.

Minting the token is NOT implemented here — swarm-queue-client already
owns the client_credentials request, its error type and its CA handling,
and a token-endpoint fix has to be findable in one place. What this crate
adds is the agent-shaped half: the client id arrives as a *file* beside
the secret, so nothing outside nix/agent-modules/queue.nix spells
`hive-<name>-agent` twice. That is the same problem hive-agent's
swarm_queue module solves, and swarm-logs/src/auth.rs is its `decide`
restated over this binary's inputs.

⚠️ The plan named one thing to verify empirically before calling the auth
settled: whether authelia's bearer policy for the logs vhost accepts the
agent client's audience. Measured from inside a container: it does not.
The client minted a token fine but with `aud: []` and `scp: []`, asking
for the logs URL as an audience answered `invalid_target`, and presenting
the audience-less token to the gateway answered a bare 401. So
swarm-authelia.nix's agentClients gains `authelia.bearer.authz` and the
query URL as a second audience — authelia authorises a bearer token by
the URL being requested, and that URL is now one binding read by three
places rather than three spellings of one address.

The URL reaches an agent the same way its queue coordinates do: computed
on the host (a container cannot derive a gateway address), forwarded by
hive_c0re::meta into the container's option set, and consumed by a new
agent module that installs the binary *wrapped* with its coordinates —
the shape swarm-controller.nix installs swarmctl in. Gated on the queue
credential as well as on the URL: a binary that can only answer 401 is
worse than no binary, because an agent reads a 401 as "no logs", which is
the exact confusion the store's machine route was added to end.
2026-09-17 01:02:14 +02:00
..
agent_config refactor(hive-c0re): drop the request_init_config tool and InitConfig approval 2026-09-14 19:03:44 +02:00
dashboard refactor(hive-c0re): drop the request_init_config tool and InitConfig approval 2026-09-14 19:03:44 +02:00
forge hive-c0re: fast-forward applied/<name>/main too, not just the one-shot relock 2026-09-13 17:33:58 +02:00
job_queue hive-c0re: validate cascade agent names in meta_update_cascade_agents' fanout path too 2026-09-13 17:33:58 +02:00
lifecycle refactor(hive-c0re): drop the request_init_config tool and InitConfig approval 2026-09-14 19:03:44 +02:00
socket_server refactor(hive-c0re): drop the request_init_config tool and InitConfig approval 2026-09-14 19:03:44 +02:00
stats AgentStatusRow: carry active_model + set_status text/timestamp 2026-09-07 14:08:30 +02:00
stores refactor(hive-c0re): drop the request_init_config tool and InitConfig approval 2026-09-14 19:03:44 +02:00
workers remove as_str() legacy wrappers, callers use .into() directly 2026-09-12 00:06:31 +02:00
actions.rs refactor(hive-c0re): drop the request_init_config tool and InitConfig approval 2026-09-14 19:03:44 +02:00
container_view.rs add per-agent url to host.sock agent status rows 2026-09-07 20:30:38 +02:00
coordinator.rs refactor(hive-c0re): drop the request_init_config tool and InitConfig approval 2026-09-14 19:03:44 +02:00
dashboard_events.rs remove the 1NFR4 dashboard panel and the now-writer-less audit log 2026-08-31 00:18:21 +02:00
gateway_nginx.rs gateway: $connection_upgrade does not come from recommendedProxySettings 2026-09-02 09:04:24 +02:00
loose_ends.rs hive-sh4re: one saturating_age for every loose-end producer 2026-09-02 14:20:25 +02:00
main.rs hive-c0re: publish each agent's status upward to the swarm queue (#3341 item 1) 2026-09-02 09:01:38 +02:00
matrix.rs matrix: remove the registration token 2026-09-15 19:58:10 +02:00
meta.rs swarm-logs: an agent's CLI for the swarm log store 2026-09-17 01:02:14 +02:00
migrate.rs docs: repoint eighteen pointers whose section no longer exists 2026-09-02 09:00:23 +02:00
paths.rs matrix: create accounts as the appservice, and promote the admin explicitly 2026-09-15 19:29:13 +02:00
priv_client.rs remove hive-level infra-container restart from web ui and agents 2026-08-31 00:18:21 +02:00
server.rs matrix: create accounts as the appservice, and promote the admin explicitly 2026-09-15 19:29:13 +02:00
snapshot_push.rs refactor(#2862): one snapshot store per swarm, not one per peer 2026-07-31 22:15:37 +02:00
swarm_agent_status.rs swarm: present tense + no-queue-coordinates wording 2026-09-13 12:01:58 +02:00
swarm_notices.rs swarm: present tense + no-queue-coordinates wording 2026-09-13 12:01:58 +02:00
swarm_queue.rs swarm-queue-based lifecycle notices, replacing push_todo(MANAGER_AGENT) 2026-08-24 14:34:37 +02:00
swarm_status.rs hive-c0re: converge when the controller republishes, not only at boot 2026-09-03 00:36:57 +02:00
test_env.rs test(hive-c0re): one crate-wide lock for env-mutating tests 2026-08-19 01:38:54 +02:00
webhook_secret.rs chore(#2510): bump indicatif/tower-http/hmac/sha2 to latest majors 2026-07-16 10:42:30 +02:00