a swarm o agents, each in its own nspawn cage, gossiping over unix sockets. config changes flow as git commits, the operator approves them in a browser, every deploy is a tag. cyberpunk-themed dashboard included. 💜
  • Rust 64.2%
  • Nix 21.3%
  • JavaScript 5.3%
  • TypeScript 4.5%
  • CSS 3.2%
  • Other 1.5%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas f1445b4c8b swarm-bao: give each hive-cert consumer its own bao identity
Four units read one path each out of the store, and all four logged in
holding `deploy.bao.clientCertFile` — the hive's own leaf. Bao identifies
a principal by the subject of the certificate it presents, so four
readers behind one certificate were ONE principal, and the only grant
expressible was the union of what the four need: read on
`swarm/agents/*`, `swarm/hives/<hive>/*` and `swarm/services/*`. The unit
fetching Grafana's OIDC client secret could fetch every agent credential
in the swarm; the one fetching this hive's matrix token could fetch
Grafana's. Least privilege was not misconfigured here, it was
unrepresentable.

Each now holds a leaf, a cert-auth role and a policy of its own, and each
policy is the single `secret/data/…` path that unit's own script names —
spelled to the leaf, not to a prefix, the way matrix-ctl's already is.
Following the four exemplars in-tree rather than building a mechanism:
`signLeaf` mints the leaves, `swarm-bao.nix` writes the roles from the
bootstrap token, the consumers name their own pair.

Two of the four are written PER HIVE and two are not, which is the shape
of the paths rather than a preference. A matrix appservice token and a
queue credential live under `swarm/hives/<name>/` and every hive runs a
reader for its own, so one role for all of them would have to be granted
`hives/*` — letting one hive read another's, a reach no hive has today.
An OIDC client secret lives under `swarm/services/<client-id>/` and a
swarm registers each exactly once, so one role each is enough. The
per-hive subjects are `<prefix>-<hive>` and swarm.nix reserves every
composed spelling as a hive name, so a hive cannot be named into another
hive's role.

The shared leaf stays: hive-c0re still passes it into its container, the
`bao` CLI wrapper still defaults to it, and the three
`glue-*-bao-identity.nix` files derive the PKI directory from it.

module-eval-bao-grants gains a negative arm per principal — each pins the
three stanzas the hive's leaf carried and the two wildcards a later
widening would reach for, so a policy that grows fails here rather than
in a store. Plus the consuming side: repointing a unit back at the hive's
leaf would evaluate, deploy and log in, and silently restore the union.

A hive that reads a store on another machine now places one leaf per
principal instead of one shared by four. That cost is the point, and
docs/swarm/secrets.md lists the pairs.
2026-09-23 10:11:42 +02:00
.forgejo/workflows ci: add dashboard-description lint 2026-09-20 14:42:39 +02:00
branding swarm-ui: make it installable as a PWA 2026-09-12 11:30:20 +02:00
claude-plugins claude-plugins: format the swarm-logs skill with nix fmt 2026-09-17 15:17:33 +02:00
docs swarm-bao: give each hive-cert consumer its own bao identity 2026-09-23 10:11:42 +02:00
frontend docs: retire the agent hierarchy from every page that described it 2026-09-21 22:08:47 +02:00
hive-agent docs+comments: say what changed instead of tagging the tracker item 2026-09-21 22:43:16 +02:00
hive-agent-mcp docs+comments: say what changed instead of tagging the tracker item 2026-09-21 22:43:16 +02:00
hive-agent-sock hive-c0re: render the new agent option paths into generated agent flakes 2026-09-17 20:19:30 +02:00
hive-bash-mcp hive-bash-mcp: drop the redundant output-path line from status's description 2026-09-13 15:56:10 +02:00
hive-c0re docs+comments: say what changed instead of tagging the tracker item 2026-09-21 22:43:16 +02:00
hive-core-agent-sock remove the get_host_journal MCP tool and its capability 2026-09-21 19:31:45 +02:00
hive-forge hive-forge: ci-rerun --run refuses on a PR-triggered run too 2026-09-21 21:37:22 +02:00
hive-forge-notify hive-forge-notify: fix notify.rs's dangling doc pointer 2026-09-11 09:04:46 +02:00
hive-host-sock topology: drop the parent field and the hierarchy it fed 2026-09-21 22:08:47 +02:00
hive-jobq treefmt: apply prettier 2026-09-02 15:25:07 +02:00
hive-jobq-metrics move otel_http_client from swarm-queue-client into swarm-controller 2026-08-29 11:17:24 +02:00
hive-jobq-wire address review: move parse_states/filter_nodes_by_state to hive-jobq-wire, rename placeholder enums, trim core-mirroring framing 2026-08-16 16:59:54 +02:00
hive-log log: send records natively to journald, keep stdout off-unit 2026-09-21 15:52:57 +02:00
hive-matrix-mcp matrix: make the hive-internal main account an ordinary matrixAccounts entry 2026-09-18 09:34:44 +02:00
hive-metric docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
hive-priv remove the get_host_journal MCP tool and its capability 2026-09-21 19:31:45 +02:00
hive-priv-sock hive-c0re: render the new agent option paths into generated agent flakes 2026-09-17 20:19:30 +02:00
hive-screen-mcp hive-c0re: render the new agent option paths into generated agent flakes 2026-09-17 20:19:30 +02:00
hive-sh4re topology: drop the parent field and the hierarchy it fed 2026-09-21 22:08:47 +02:00
hive-sock-client treefmt: apply prettier 2026-09-02 15:25:07 +02:00
hive-subagent-mcp hive-subagent-mcp: fold the task out of the system prompt on the no-role path too 2026-09-21 17:21:40 +02:00
hive-types docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00
hivectl topology: drop the parent field and the hierarchy it fed 2026-09-21 22:08:47 +02:00
nix swarm-bao: give each hive-cert consumer its own bao identity 2026-09-23 10:11:42 +02:00
scripts check-issue-refs.sh: scan .ini files too; drop tracker tags from .vale.ini 2026-09-20 18:59:46 +02:00
swagger-ui-theme treefmt: apply prettier 2026-09-02 15:25:07 +02:00
swarm-authelia-bridge check-issue-refs: catch full forge issue URLs too, drop internal links from docs entirely 2026-09-09 21:15:28 +02:00
swarm-authelia-bridge-sock feat(swarm-authelia-bridge): report a heal as its own outcome 2026-08-23 19:00:41 +02:00
swarm-controller swarm-controller: pin what the backfill route queues 2026-09-21 20:38:55 +02:00
swarm-logs docs: gate write-good.Passive on CI 2026-09-20 16:24:11 +02:00
swarm-matrix-ctl matrix: one sender account and one sender token per hive 2026-09-20 22:07:16 +02:00
swarm-nats-auth swarm-nats-auth: accept the agent suffix it ships as its default 2026-09-12 12:03:54 +02:00
swarm-queue-client swarm-queue-client: trim token_request comment block under the 30-line lint 2026-09-17 10:03:27 +02:00
swarm-secret-client swarm: mint a per-agent queue credential beside the agent's store identity 2026-09-21 20:38:55 +02:00
swarmctl docs: clear the vale errors the queue-credential prose introduced 2026-09-21 20:38:55 +02:00
.gitignore docs: address review — redundancy proof for Passive, wave-2 split, re-enable Contractions 2026-09-07 11:56:31 +02:00
.mailmap chore(#2165): add damocles@pr1ma + lexis@pr1ma mailmap entries 2026-07-04 13:50:16 +02:00
.prettierignore swarm-logs-cli.md: regenerate from the binary, prettierignore it 2026-09-17 01:02:14 +02:00
.prettierrc temp: add prettier configs 2026-07-02 23:33:11 +02:00
.vale.ini check-issue-refs.sh: scan .ini files too; drop tracker tags from .vale.ini 2026-09-20 18:59:46 +02:00
Cargo.lock swarm: mint a per-agent queue credential beside the agent's store identity 2026-09-21 20:38:55 +02:00
Cargo.toml swarm: mint a per-agent queue credential beside the agent's store identity 2026-09-21 20:38:55 +02:00
CLAUDE.md log: send records natively to journald, keep stdout off-unit 2026-09-21 15:52:57 +02:00
clippy.toml swarm-logs: an agent's CLI for the swarm log store 2026-09-17 01:02:14 +02:00
flake.lock nix flake update 2026-09-22 23:15:29 +02:00
flake.nix swarm-matrix-ctl: one control binary for the matrix container, not one per job 2026-09-20 22:07:16 +02:00
README.md docs/hive-c0re: fix ask/answer removal doc gaps argus caught on #3741 2026-08-30 03:02:31 +02:00

hyperhive

a swarm of claude-code agents, each in its own nspawn cage, gossiping over unix sockets. config changes flow as git commits, the operator approves them in a browser, every deploy is a tag. cyberpunk-themed dashboard included. 💜

Claude code is great in one window, exponentielle across many — but only if you can keep the agents from stepping on each other, give them durable identity, and stop them from eating production. hyperhive is the substrate.

  • identity = unix socket
  • communication = sqlite-backed broker (send / recv / remind)
  • config = git (manager proposes, operator approves, deploys land as tagged commits)
  • blast radius = container
every hive (NixOS host, runs hive-c0re.service)
│
├── operator
│   ├── browser → :80 (hive-gateway)    dashboard + per-agent UIs
│   │                                   /agent/<name>/ → per-agent unix socket
│   └── CLI     → /run/hyperhive/host.sock   admin protocol
│
├── hive-c0re  (Rust daemon: lifecycle / broker / approvals /
│               auto-update / dashboard / sockets)
│
├── hive-gateway (optional)   nginx — proxies :80 → c0re dashboard + per-agent sockets
│
└── agent containers
    ├── h-ruth     manager (privileged MCP surface, approval gating)
    └── h-<name>   sub-agent (claude + MCP tools + per-agent web UI + unix socket)

one host per swarm (optional — connects hives; can be any hive, including
one that's also running the tree above)
│
├── hive-forge             Forgejo — swarm-wide singleton, per-agent accounts + config mirror
├── hive-matrix            tuwunel — swarm-wide singleton, Matrix homeserver + per-agent accounts
├── swarm-controller       cross-hive state: hive directory, agent roster, jobs
├── swarm-ui               swarm-wide SPA, served straight off the gateway (no own container)
├── swarm-authelia         SSO — one login gates swarm-ui + Grafana + more
├── swarm-nats             message queue (JetStream KV: hive-status, …)
├── swarm-otel             telemetry collector, sole holder of the upstream credential
├── swarm-victoriametrics  metrics store
├── swarm-victorialogs     log store
└── swarm-grafana          dashboards over the metrics/log stores, own OIDC login

→ website · → docs · → options reference

Depth lives in docs/ (rendered at hyperhive.darkest.space/docs/) — start at docs/README.md and pick the page matching your task rather than reading front to back.

Quick start

Minimal flake.nix for a host that runs hive-c0re:

{
  inputs = {
    nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";
    hyperhive.url = "git+https://forge.darkest.space/hyperhive/hyperhive";
    # Pin hyperhive to your own nixpkgs instead of the one it ships with
    # (see "Overriding nixpkgs" below) — recommended for most hosts:
    hyperhive.inputs.nixpkgs.follows = "nixpkgs";
  };

  outputs = { nixpkgs, hyperhive, ... }: {
    nixosConfigurations.my-host = nixpkgs.lib.nixosSystem {
      system = "x86_64-linux";
      modules = [
        hyperhive.nixosModules.default  # hive-c0re + hive-forge + hive-gateway in one import
        ({ ... }: {
          services.hyperhive.enable = true;
          # services.hyperhive.c0re.operatorPronouns = "they/them";  # default: "she/her"

          # ... rest of your host config
          system.stateVersion = "25.11";
        })
      ];
    };
  };
}

hive-c0re opens its admin socket + dashboard, auto-creates the manager container, and auto-rebuilds any container whose hyperhive rev goes stale. claude-code is unfree — hyperhive scopes the whitelist to itself, nothing for the operator to set.

Overriding nixpkgs

hyperhive pins its own nixpkgs so it builds standalone in CI. Add hyperhive.inputs.nixpkgs.follows = "nixpkgs" (as in the quick-start above) to build it against your host's nixpkgs instead — one less nixpkgs evaluation, no version drift from the rest of your system. Standard flake follows pattern; works as long as your channel is reasonably close to the nixos-26.05 hyperhive develops against. Drop it again if a much older/newer channel hits breakage hyperhive's CI doesn't catch.

For the full list of host and agent NixOS options see the options reference.

Operator CLI

hivectl is the operator-facing host CLI for ad-hoc administration that doesn't go through the broker (built alongside hive-c0re when the host module is enabled):

sudo hivectl forge create-user mara                       # provisions a forge user
sudo hivectl forge create-user mara --password 'hunter2'  # … with a fixed password
sudo hivectl matrix create-user mara                      # provisions a matrix user
sudo hivectl matrix create-user mara --password-stdin     # … reading one line from stdin

For a name that's a managed agent, hivectl persists the resulting token to that agent's state dir, the same as the boot sweep does. For a non-agent name (e.g. the operator's own forge/matrix account), it prints the token to stdout and writes nothing.

Build / deploy

nix develop -c cargo check
nix flake check        # rust + nix + toml fmt + clippy

# deploy from a host config that imports hyperhive.nixosModules.default
nix flake update --update-input hyperhive
sudo nixos-rebuild switch --flake .#<host>