OpenBao in a swarm-bao nixos-container, unsealed by the host TPM through the built-in pkcs11 seal, with shamir as the documented opt-out for hardware that has no TPM. The seal guard asks the package whether it was built with an HSM rather than reading its version, and falls back to the version cliff only when a package advertises no tags -- it fails closed. Every listener serves TLS: loopback unconditionally, because the host running the store is always one of its readers, plus whatever extraListenAddresses names, because which network the other hives share is a deployment fact. Client-certificate verification turns on only when clientCaFile says what to trust. The store's identity is an input, and nothing in THIS module fills it in. Service-to-store mTLS is a separate trust domain from the gateway's HTTPS certificates and from both CAs in this tree: a store must not take its identity from an authority it will itself distribute, or it cannot come up before the thing that issues it. The module asserts when the paths are unset rather than reaching for whichever CA happens to be wired; what supplies them on a self-contained deploy is the next commit. The leaf is copied to the container's state dir by a host unit rather than bind-mounted: nixos-container refuses to start when a bind source is missing, and a directory holding a leaf usually holds the CA's key beside it.
42 lines
1.3 KiB
Nix
42 lines
1.3 KiB
Nix
# The full hyperhive host stack, pulled together in one place — this
|
|
# is what the flake exports as `nixosModules.default` (wrapped with
|
|
# the package/source wiring; see flake.nix). One import covers
|
|
# everything; `services.hyperhive.enable = true` turns the stack on.
|
|
#
|
|
# The forge is mandatory — hive-c0re mirrors every agent's applied
|
|
# config repo into it and it's the canonical store for the meta flake
|
|
# + `internal/*` repos, so there's no enable toggle; it deploys with
|
|
# hyperhive itself. hive-matrix is opt-in (off by default). All
|
|
# subsystems rely on `services.hyperhive.domain`, which is required
|
|
# (asserted in hive-network.nix) whenever hyperhive is enabled.
|
|
{
|
|
imports = [
|
|
./hyperhive.nix
|
|
./deploy.nix
|
|
./local-defaults.nix
|
|
./hive-c0re
|
|
./hive-ci.nix
|
|
./hive-forge
|
|
./hive-gateway
|
|
./hive-matrix.nix
|
|
./hive-network.nix
|
|
./hive-priv.nix
|
|
./hive-tls.nix
|
|
./otel.nix
|
|
./swarm-authelia.nix
|
|
./swarm-bao.nix
|
|
./swarm-ca.nix
|
|
./swarm-nats.nix
|
|
./swarm-controller.nix
|
|
./swarm-grafana.nix
|
|
./swarm-otel.nix
|
|
./swarm-snapshot-store.nix
|
|
./swarm-ui.nix
|
|
./swarm-victorialogs.nix
|
|
./swarm-victoriametrics.nix
|
|
./swarm-wireguard.nix
|
|
./swarm.nix
|
|
./swarm-peers-removed.nix
|
|
./swarm-required-services.nix
|
|
];
|
|
}
|