Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/nix/host-modules
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas ed2ec52fe5 swarm-tls: narrow each gateway's services leaf to the names it fronts
Every gateway asked the store's `pki/issue/swarm-services` for the whole
swarm's service set, so a private key on any gateway host could serve a
valid certificate for services that host does not front and never has.

`swarm.localServiceDomains` derives the per-host subset by filtering
`swarm.serviceDomains` against the vhosts this host actually renders —
the deploy flags those vhosts are already guarded on, read once rather
than copied into a second filter. The leaf request and the coverage
guard that decides whether to re-issue both read it, so they cannot
disagree about which names the leaf owes.

The sub-CA's name constraint and the role's `allowed_domains` stay the
swarm-wide set: every host's subset is inside it, and narrowing the
constraint per host would turn one signing into N.
2026-09-25 23:41:10 +02:00
..
hive-c0re swarm-controller: own the swarm-wide forge objects; hive-c0re stops creating them 2026-09-25 08:36:05 +02:00
hive-forge swarm-controller: own the swarm-wide forge objects; hive-c0re stops creating them 2026-09-25 08:36:05 +02:00
hive-gateway nix: ship the journals of the units an apply can leave failed 2026-09-24 15:14:44 +02:00
lib swarm: extract the name guards, so the module just says what is forbidden 2026-08-31 18:50:15 +02:00
swarm-grafana/dashboards swarm-grafana: replace busiest-agents bargauges with an actual table 2026-09-20 23:40:21 +02:00
default.nix nix: run the forge on one host per swarm (deploy.forgejo.enable) 2026-09-24 23:56:07 +02:00
deploy.nix nix: run the forge on one host per swarm (deploy.forgejo.enable) 2026-09-24 23:56:07 +02:00
glue-bao-readers-policy-order.nix swarm-bao: give the store forwarder's OIDC reader its own bao identity 2026-09-25 00:37:31 +02:00
glue-bao-tls.nix swarm-bao: give the store forwarder's OIDC reader its own bao identity 2026-09-25 00:37:31 +02:00
glue-controller-bao-identity.nix swarm-controller: hand the daemon the authority hives are issued from 2026-09-10 00:25:07 +02:00
glue-forge-oidc-client.nix nix: run the forge on one host per swarm (deploy.forgejo.enable) 2026-09-24 23:56:07 +02:00
glue-grafana-oidc-client.nix nix: run the forge on one host per swarm (deploy.forgejo.enable) 2026-09-24 23:56:07 +02:00
glue-matrix-bao-token.nix nix: move the reader-after-policy edges into their own colocation glue 2026-09-24 15:15:15 +02:00
glue-matrix-ctl-bao-identity.nix swarm-matrix-ctl: one control binary for the matrix container, not one per job 2026-09-20 22:07:16 +02:00
glue-nats-bao-identity.nix swarm-nats: give the queue a name, a bao-issued leaf, and require TLS 2026-09-24 17:26:31 +02:00
glue-queue-agent-credential.nix nix: move the reader-after-policy edges into their own colocation glue 2026-09-24 15:15:15 +02:00
glue-secret-publisher-bao-identity.nix swarm: publish minted OIDC client secrets into the swarm store 2026-09-12 11:22:33 +02:00
glue-services-issuer-bao-identity.nix nix: issue the swarm-services leaf from bao's pki mount 2026-09-23 21:00:02 +02:00
glue-swarm-bao-otel-oidc-client.nix nix: the store's own collector scrapes its metrics listener 2026-09-21 17:19:52 +02:00
glue-swarm-otel-oidc-client.nix swarm-otel: deliver the OIDC client secret through the secret store 2026-09-14 00:58:58 +02:00
hive-ci.nix nix: run the forge on one host per swarm (deploy.forgejo.enable) 2026-09-24 23:56:07 +02:00
hive-matrix.nix hive-matrix: load the swarm's appservice and promote its sender 2026-09-25 08:31:01 +02:00
hive-network.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
hive-priv.nix docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
hive-tls.nix swarm-tls: narrow each gateway's services leaf to the names it fronts 2026-09-25 23:41:10 +02:00
hyperhive.nix docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
local-defaults.nix swarm: default every queue URL to the queue's name on every hive 2026-09-24 17:26:31 +02:00
otel.nix otel.nix: trim the StartLimit comment block to the load-bearing points 2026-09-23 17:22:51 +02:00
stylix-theme.nix swarm-ui: apply the operator's stylix theme, same as the dashboard already does 2026-08-24 14:28:25 +02:00
swarm-authelia.nix nix: make swarm.authelia.url non-nullable, trim its docs 2026-09-21 18:14:28 +02:00
swarm-bao-bootstrap-policy.hcl swarm-bao: give the store forwarder's OIDC reader its own bao identity 2026-09-25 00:37:31 +02:00
swarm-bao.nix hive-tls: renew the swarm-services leaf on a daily timer 2026-09-25 23:38:36 +02:00
swarm-ca.nix nix: issue the swarm-services leaf from bao's pki mount 2026-09-23 21:00:02 +02:00
swarm-container-resolver.nix fix(#3363): swarm containers write their own resolver file 2026-08-17 17:30:15 +02:00
swarm-controller.nix swarm-controller: own the swarm-wide forge objects; hive-c0re stops creating them 2026-09-25 08:36:05 +02:00
swarm-grafana.nix nix: move the reader-after-policy edges into their own colocation glue 2026-09-24 15:15:15 +02:00
swarm-nats.nix swarm-nats: give the queue a name, a bao-issued leaf, and require TLS 2026-09-24 17:26:31 +02:00
swarm-otel.nix swarm-otel: correct the hostJournalDir comment for swarm-bao's exception 2026-09-25 04:02:08 +02:00
swarm-peers-removed.nix docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
swarm-required-services.nix nix: run the forge on one host per swarm (deploy.forgejo.enable) 2026-09-24 23:56:07 +02:00
swarm-secret-publisher.nix nix: the store's own collector scrapes its metrics listener 2026-09-21 17:19:52 +02:00
swarm-snapshot-store.nix deploy: move the wireguard mesh out of the namespace hives read 2026-09-07 14:24:52 +02:00
swarm-ui.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
swarm-victorialogs.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
swarm-victoriametrics.nix nix: give the gateway, resolver and bridge their own enable 2026-09-19 13:53:10 +02:00
swarm-wireguard.nix deploy: move the wireguard mesh out of the namespace hives read 2026-09-07 14:24:52 +02:00
swarm.nix swarm-tls: narrow each gateway's services leaf to the names it fronts 2026-09-25 23:41:10 +02:00