hyperhive/nix/host-modules
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas fa540ca1ec swarm-bao: run the swarm's secret store in a container
OpenBao in a swarm-bao nixos-container, unsealed by the host TPM through
the built-in pkcs11 seal, with shamir as the documented opt-out for
hardware that has no TPM. The seal guard asks the package whether it was
built with an HSM rather than reading its version, and falls back to the
version cliff only when a package advertises no tags -- it fails closed.

Every listener serves TLS: loopback unconditionally, because the host
running the store is always one of its readers, plus whatever
extraListenAddresses names, because which network the other hives share
is a deployment fact. Client-certificate verification turns on only when
clientCaFile says what to trust.

The store's identity is an input, and nothing in THIS module fills it
in. Service-to-store mTLS is a separate trust domain from the gateway's
HTTPS certificates and from both CAs in this tree: a store must not take
its identity from an authority it will itself distribute, or it cannot
come up before the thing that issues it. The module asserts when the
paths are unset rather than reaching for whichever CA happens to be
wired; what supplies them on a self-contained deploy is the next commit.

The leaf is copied to the container's state dir by a host unit rather
than bind-mounted: nixos-container refuses to start when a bind source
is missing, and a directory holding a leaf usually holds the CA's key
beside it.
2026-08-30 19:01:10 +02:00
..
hive-c0re matrix: forward the homeserver URL from client hives too 2026-08-30 15:17:02 +02:00
hive-forge deploy: move the forge CI runner toggle out of swarm 2026-08-30 16:07:21 +02:00
hive-gateway gateway: move verifiedProxyTo's 42-line rationale comment to docs/gateway.md 2026-08-28 10:48:26 +02:00
lib fix(#3527): a missing source must report as zero, not as empty 2026-08-19 20:27:00 +02:00
swarm-grafana/dashboards grafana: rank the by-label panel as bars, and stop calling it open issues 2026-08-28 13:23:25 +02:00
default.nix swarm-bao: run the swarm's secret store in a container 2026-08-30 19:01:10 +02:00
deploy.nix deploy: which host runs the secret store is its own decision 2026-08-30 18:54:35 +02:00
hive-ci.nix deploy: move the forge CI runner toggle out of swarm 2026-08-30 16:07:21 +02:00
hive-matrix.nix deploy: move the matrix homeserver toggle out of swarm 2026-08-30 15:17:02 +02:00
hive-network.nix require network isolation, deleting the residual non-isolated branch 2026-08-30 03:32:08 +02:00
hive-priv.nix fix(#2573): also add /etc/tmpfiles.d to hive-priv ReadWritePaths (same EROFS class) 2026-07-18 16:39:20 +02:00
hive-tls.nix deploy: give every option an enable, and name the controller one 2026-08-30 04:23:22 +02:00
hyperhive.nix refactor(nix): a hive's domain comes out of the swarm directory 2026-08-05 22:43:17 +02:00
local-defaults.nix local-defaults: assert the controller through deploy, not the old alias 2026-08-30 04:23:22 +02:00
otel.nix deploy: name the swarm collector swarm-otel, not otel 2026-08-30 04:23:22 +02:00
stylix-theme.nix swarm-ui: apply the operator's stylix theme, same as the dashboard already does 2026-08-24 14:28:25 +02:00
swarm-authelia.nix deploy: name the swarm collector swarm-otel, not otel 2026-08-30 04:23:22 +02:00
swarm-bao.nix swarm-bao: run the swarm's secret store in a container 2026-08-30 19:01:10 +02:00
swarm-ca.nix swarm-otel: collect only the units the swarm's services declare 2026-08-24 22:05:45 +02:00
swarm-container-resolver.nix fix(#3363): swarm containers write their own resolver file 2026-08-17 17:30:15 +02:00
swarm-controller.nix deploy: name the swarm collector swarm-otel, not otel 2026-08-30 04:23:22 +02:00
swarm-grafana.nix deploy: name the swarm collector swarm-otel, not otel 2026-08-30 04:23:22 +02:00
swarm-nats.nix deploy: name the swarm collector swarm-otel, not otel 2026-08-30 04:23:22 +02:00
swarm-otel.nix deploy: name the swarm collector swarm-otel, not otel 2026-08-30 04:23:22 +02:00
swarm-peers-removed.nix docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
swarm-required-services.nix deploy: which host runs the secret store is its own decision 2026-08-30 18:54:35 +02:00
swarm-snapshot-store.nix refactor(#2862): keep the option at services.hyperhive.snapshotStore 2026-07-31 19:03:24 +02:00
swarm-ui.nix deploy: give every option an enable, and name the controller one 2026-08-30 04:23:22 +02:00
swarm-victorialogs.nix deploy: retention is the store host's decision, not the swarm's 2026-08-30 16:23:48 +02:00
swarm-victoriametrics.nix deploy: retention is the store host's decision, not the swarm's 2026-08-30 16:23:48 +02:00
swarm-wireguard.nix docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294) 2026-08-15 19:56:11 +02:00
swarm.nix deploy: name the swarm collector swarm-otel, not otel 2026-08-30 04:23:22 +02:00