atlas
fb9c6122df
matrix: name the credential after the account it authenticates as
...
The store path and every identifier around it called this an admin
token. It is not one: of ~15 hive-c0re call sites only two need
homeserver admin, and the homeserver no longer promotes the account at
boot, so the name overstated both what the credential is and what it may
do.
Renaming it to the account was not enough either. "The `@hive:` token"
reads as the token of a hive user, and no such user is provisioned —
`@hive:<server_name>` is the appservice registration's own
`sender_localpart`, an account the homeserver creates for itself when it
loads the registration.
So it is the **sender token**: the matrix appservice sender account's
access token, at `swarm/services/matrix/sender-token`. The name says
what it authenticates as rather than what it may do, which is the part
that was wrong.
The path has one constructor, and the bao grant, the grant assertion and
three unit tests pin its literal independently — so a half-finished
rename fails a check rather than leaving the minter and its readers
disagreeing at runtime. `tracing` messages are renamed with the code, so
the journal reads the way the source does.
The host-side file keeps its name (`matrix/access-token`): it carried no
admin framing, and renaming it would orphan the file on every deployed
hive for nothing.
`docs/tools/hivectl-cli.md` is regenerated from the clap tree.
2026-09-20 22:07:16 +02:00
..
hive-c0re
nix: give the gateway, resolver and bridge their own enable
2026-09-19 13:53:10 +02:00
hive-forge
nix: give the gateway, resolver and bridge their own enable
2026-09-19 13:53:10 +02:00
hive-gateway
docs(gateway): describe nginx as per-host, not a deployment-wide singleton
2026-09-19 13:58:10 +02:00
lib
swarm: extract the name guards, so the module just says what is forbidden
2026-08-31 18:50:15 +02:00
swarm-grafana /dashboards
swarm-grafana: sort logstore bargauge panels by value
2026-09-20 20:02:42 +02:00
default.nix
matrix: mint the appservice sender token in the matrix container
2026-09-20 22:07:16 +02:00
deploy.nix
swarm-controller: make socketPath readOnly instead of asserting it
2026-09-17 19:27:30 +02:00
glue-bao-tls.nix
matrix: mint the appservice sender token in the matrix container
2026-09-20 22:07:16 +02:00
glue-controller-bao-identity.nix
swarm-controller: hand the daemon the authority hives are issued from
2026-09-10 00:25:07 +02:00
glue-grafana-oidc-client.nix
swarm-grafana: deliver the OIDC client secret through the secret store
2026-09-13 19:57:28 +02:00
glue-matrix-bao-token.nix
matrix: remove the registration token
2026-09-15 19:58:10 +02:00
glue-matrix-minter-bao-identity.nix
matrix: mint the appservice sender token in the matrix container
2026-09-20 22:07:16 +02:00
glue-queue-agent-credential.nix
matrix: remove the registration token
2026-09-15 19:58:10 +02:00
glue-secret-publisher-bao-identity.nix
swarm: publish minted OIDC client secrets into the swarm store
2026-09-12 11:22:33 +02:00
glue-swarm-otel-oidc-client.nix
swarm-otel: deliver the OIDC client secret through the secret store
2026-09-14 00:58:58 +02:00
hive-ci.nix
nix: give the gateway, resolver and bridge their own enable
2026-09-19 13:53:10 +02:00
hive-matrix.nix
matrix: name the credential after the account it authenticates as
2026-09-20 22:07:16 +02:00
hive-network.nix
nix: give the gateway, resolver and bridge their own enable
2026-09-19 13:53:10 +02:00
hive-priv.nix
docs: restructure into topic subdirectories, collapse duplicated index
2026-09-02 01:55:37 +02:00
hive-tls.nix
docs: restructure into topic subdirectories, collapse duplicated index
2026-09-02 01:55:37 +02:00
hyperhive.nix
docs: restructure into topic subdirectories, collapse duplicated index
2026-09-02 01:55:37 +02:00
local-defaults.nix
bao: write the swarm controller's policy from inside the store
2026-09-07 18:43:09 +02:00
otel.nix
nix: give the gateway, resolver and bridge their own enable
2026-09-19 13:53:10 +02:00
stylix-theme.nix
swarm-ui: apply the operator's stylix theme, same as the dashboard already does
2026-08-24 14:28:25 +02:00
swarm-authelia.nix
nix: derive hive identities and the token endpoint from the swarm, not this host
2026-09-19 14:31:19 +02:00
swarm-bao.nix
matrix: name the credential after the account it authenticates as
2026-09-20 22:07:16 +02:00
swarm-ca.nix
swarm-ca: state the store-is-world-readable rule once, not three times
2026-09-02 09:03:35 +02:00
swarm-container-resolver.nix
fix( #3363 ): swarm containers write their own resolver file
2026-08-17 17:30:15 +02:00
swarm-controller.nix
nix: drop the central-toggle conjunct from four compound gates
2026-09-19 10:48:12 +02:00
swarm-grafana.nix
grafana: move logLevelRules implementation notes to docs
2026-09-20 17:39:04 +02:00
swarm-nats.nix
nix: give the gateway, resolver and bridge their own enable
2026-09-19 13:53:10 +02:00
swarm-otel.nix
otel: map journald PRIORITY onto a severity at every journald receiver
2026-09-20 14:23:56 +02:00
swarm-peers-removed.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm-required-services.nix
nix: give the gateway, resolver and bridge their own enable
2026-09-19 13:53:10 +02:00
swarm-secret-publisher.nix
matrix: publish the appservice token from the swarm, not just read it
2026-09-15 20:57:49 +02:00
swarm-snapshot-store.nix
deploy: move the wireguard mesh out of the namespace hives read
2026-09-07 14:24:52 +02:00
swarm-ui.nix
nix: give the gateway, resolver and bridge their own enable
2026-09-19 13:53:10 +02:00
swarm-victorialogs.nix
nix: give the gateway, resolver and bridge their own enable
2026-09-19 13:53:10 +02:00
swarm-victoriametrics.nix
nix: give the gateway, resolver and bridge their own enable
2026-09-19 13:53:10 +02:00
swarm-wireguard.nix
deploy: move the wireguard mesh out of the namespace hives read
2026-09-07 14:24:52 +02:00
swarm.nix
matrix: mint the appservice sender token in the matrix container
2026-09-20 22:07:16 +02:00