The harness now reads swarm/agents/<agent>/queue from the store itself, under the agent's own store certificate, and holds it in memory only. It reads once before the first connect and again on every reconnect attempt (async-nats `ConnectOptions::with_auth_callback`), so an agent whose secret was re-minted reconnects with the new value instead of being refused until the container restarts. hive-agent-queue-credential.service, the /run file it wrote, and HIVE_AGENT_QUEUE_AGENT_SECRET_FILE are gone; queue-identity.nix now hands hive-agent.service the store address, its certificate paths and the agent name. A failed or empty read before the first connect still falls back to the hive's shared client. Each read is bounded by a 10s timeout, and retries wait out the existing reconnect backoff (500ms doubling, capped at 60s). Closes #4783
57 lines
1.8 KiB
TOML
57 lines
1.8 KiB
TOML
[package]
|
|
name = "hive-agent"
|
|
edition.workspace = true
|
|
version.workspace = true
|
|
readme = "README.md"
|
|
|
|
[lints]
|
|
workspace = true
|
|
|
|
[dependencies]
|
|
anyhow.workspace = true
|
|
# Named directly for the client type the publishers hold, and for `jetstream`,
|
|
# which the icon publisher's acked write needs. The connect and the credential
|
|
# handling live in `swarm-queue-client` below.
|
|
async-nats = { workspace = true, features = ["jetstream"] }
|
|
axum.workspace = true
|
|
chrono.workspace = true
|
|
reqwest.workspace = true
|
|
hyper.workspace = true
|
|
hyper-util.workspace = true
|
|
http-body-util.workspace = true
|
|
futures-util = "0.3"
|
|
clap.workspace = true
|
|
hive-claude.workspace = true
|
|
hive-agent-sock.workspace = true
|
|
hive-core-agent-sock.workspace = true
|
|
hive-log.workspace = true
|
|
hive-sh4re.workspace = true
|
|
hive-sock-client.workspace = true
|
|
libc.workspace = true
|
|
opentelemetry.workspace = true
|
|
opentelemetry_sdk.workspace = true
|
|
opentelemetry-otlp.workspace = true
|
|
rmcp.workspace = true
|
|
rusqlite.workspace = true
|
|
schemars.workspace = true
|
|
serde.workspace = true
|
|
serde_json.workspace = true
|
|
# Bare: `kv`/`notices` name buckets and streams this harness opens neither end
|
|
# of. The terminal publisher is a plain core-subject publish, so it needs the
|
|
# connect and the payload limit and nothing from JetStream.
|
|
swarm-queue-client.workspace = true
|
|
# This agent's own queue secret, read from the store under its own certificate.
|
|
swarm-secret-client.workspace = true
|
|
tokio.workspace = true
|
|
tokio-stream.workspace = true
|
|
tower-http.workspace = true
|
|
tracing.workspace = true
|
|
|
|
[dev-dependencies]
|
|
tempfile = "3"
|
|
|
|
# Single harness serve-loop binary: `hive-agent` (from `src/main.rs`).
|
|
# The sibling MCP server is its own bin crate now (`hive-agent-mcp`).
|
|
# Privilege boundary is enforced server-side at the socket (tool
|
|
# groups / manager surface).
|
|
# See `docs/turn-loop/README.md::Harness binary shape`.
|