atlas
e0e5823080
fix( #3384 ): source the queue policy's principals from the modules that mint them
...
The auth-callout responder decides what an admitted client may publish
from two strings: the prefix marking a hive client, and the client id
allowed to read every hive's key. Both were literals in three places --
swarm-authelia.nix mints "hive-${name}", swarm-controller.nix defines
"swarm-controller", and the responder carried its own copies as clap
defaults because swarm-nats.nix passed neither.
Each producer now publishes its value as a readOnly option and the
responder's ExecStart reads them, so the agreement is one evaluation
rather than three strings that happen to be equal. Same pattern the
module already uses for `--account`, and the same argument
swarm-authelia.nix gives for publishing `machine` and `unit`.
Worth the change because the failure is silent and misattributed:
rename either principal and the responder starts denying the one that
stopped matching, a denial reaches a NATS client as a timeout rather
than an error, and a hive that is refused looks exactly like a hive
that has not reported yet.
2026-08-17 17:34:51 +02:00
..
hive-c0re
feat(swarm): wire a hive's queue coordinates for status publishing
2026-08-16 13:14:03 +02:00
hive-forge
fix: let the secret-delivery oneshots outlive their own bounded wait
2026-08-16 21:45:33 +02:00
hive-gateway
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
lib
feat(nix): issue each hive's CA under a swarm root CA
2026-08-05 15:57:50 +02:00
default.nix
feat( #3265 ): swarm metrics UI as a Grafana container
2026-08-16 22:27:05 +02:00
hive-ci.nix
feat(nix): move the forge host options under services.hyperhive.swarm
2026-08-05 03:44:53 +02:00
hive-matrix.nix
fix: let the secret-delivery oneshots outlive their own bounded wait
2026-08-16 21:45:33 +02:00
hive-network.nix
docs(3191): the gateway's comments describe a host service, not a container
2026-08-12 12:20:28 +02:00
hive-priv.nix
fix( #2573 ): also add /etc/tmpfiles.d to hive-priv ReadWritePaths (same EROFS class)
2026-07-18 16:39:20 +02:00
hive-tls.nix
fix( #3349 ): do not define a controller env key on hives with no controller
2026-08-16 20:55:39 +02:00
hyperhive.nix
refactor(nix): a hive's domain comes out of the swarm directory
2026-08-05 22:43:17 +02:00
local-defaults.nix
fix( #3343 ): move the all-local queue derivations into the deployment mode
2026-08-16 19:37:49 +02:00
otel.nix
docs( #3265 ): observability.md still said the endpoint was required
2026-08-16 22:27:05 +02:00
swarm-authelia.nix
fix( #3384 ): source the queue policy's principals from the modules that mint them
2026-08-17 17:34:51 +02:00
swarm-ca.nix
fix(nix): a missing swarm-services leaf must not kill the whole gateway
2026-08-06 00:30:22 +02:00
swarm-container-resolver.nix
fix( #3363 ): swarm containers write their own resolver file
2026-08-17 17:30:15 +02:00
swarm-controller.nix
fix( #3384 ): source the queue policy's principals from the modules that mint them
2026-08-17 17:34:51 +02:00
swarm-grafana.nix
fix( #3363 ): swarm containers write their own resolver file
2026-08-17 17:30:15 +02:00
swarm-nats.nix
fix( #3384 ): source the queue policy's principals from the modules that mint them
2026-08-17 17:34:51 +02:00
swarm-peers-removed.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm-required-services.nix
feat( #3265 ): feed the store from the collector, and derive the pair
2026-08-16 22:27:05 +02:00
swarm-snapshot-store.nix
refactor( #2862 ): keep the option at services.hyperhive.snapshotStore
2026-07-31 19:03:24 +02:00
swarm-ui.nix
swarm-controller: serve swarm-wide service quick links (hyperhive#3289)
2026-08-15 14:24:52 +02:00
swarm-victoriametrics.nix
fix( #3363 ): swarm containers write their own resolver file
2026-08-17 17:30:15 +02:00
swarm-wireguard.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm.nix
feat(swarm): wire a hive's queue coordinates for status publishing
2026-08-16 13:14:03 +02:00