atlas
fe81dcaf59
fix( #3813 ): seal with an RSA-OAEP key, the only mechanism the TPM has
...
`bao operator init` fails at the seal with CKR_MECHANISM_INVALID. The
pkcs11 seal asks for AES-GCM by default and the TPM does not offer it: a
TPM 2.0's symmetric modes are CBC/CFB/CTR/OFB/ECB, and openbao accepts
only AEAD mechanisms — AES-GCM or RSA-OAEP — so RSA-OAEP is the single
mechanism both sides implement.
Measured on the deployed token (`pkcs11-tool --list-mechanisms`, #3860 ):
no AES-GCM, and `RSA-PKCS-OAEP, keySize={1024,2048}, hw, encrypt,
decrypt` present. CBC is not a fallback — openbao's
`MechanismFromString` rejects `CKM_AES_CBC_PAD` as deprecated and its
encrypt path implements exactly the two AEAD mechanisms.
The key gets a new label so a store provisioned by the earlier module
keeps its unusable AES key without the two resolving to one label, and
the addkey step is now keyed on the label rather than on the store not
existing — otherwise an existing deployment never gains the RSA key.
2026-09-01 09:16:04 +02:00
..
hive-c0re
otel: ship the journals the dashboard can already show
2026-08-31 12:51:51 +02:00
hive-forge
swarm: remove swarm.ui.domain, serve the UI on the swarm domain
2026-08-31 19:00:52 +02:00
hive-gateway
deploy: move the hive CA's knobs to deploy.hive-controller.tls
2026-08-30 20:52:00 +02:00
lib
swarm: extract the name guards, so the module just says what is forbidden
2026-08-31 18:50:15 +02:00
swarm-grafana /dashboards
grafana: rank the by-label panel as bars, and stop calling it open issues
2026-08-28 13:23:25 +02:00
default.nix
glue-matrix-bao-token: the store's first reader
2026-08-30 19:01:10 +02:00
deploy.nix
deploy: move the hive CA's knobs to deploy.hive-controller.tls
2026-08-30 20:52:00 +02:00
glue-bao-tls.nix
swarm-bao: ship the store's logs and metrics
2026-08-31 21:25:00 +02:00
glue-matrix-bao-token.nix
swarm-bao: ship the store's logs and metrics
2026-08-31 21:25:00 +02:00
hive-ci.nix
otel: ship the journals the dashboard can already show
2026-08-31 12:51:51 +02:00
hive-matrix.nix
docs: M4TR1X page is reached via swarm-ui's LinksMenu, not opened directly
2026-08-31 12:55:40 +02:00
hive-network.nix
require network isolation, deleting the residual non-isolated branch
2026-08-30 03:32:08 +02:00
hive-priv.nix
fix( #2573 ): also add /etc/tmpfiles.d to hive-priv ReadWritePaths (same EROFS class)
2026-07-18 16:39:20 +02:00
hive-tls.nix
deploy: move the hive CA's knobs to deploy.hive-controller.tls
2026-08-30 20:52:00 +02:00
hyperhive.nix
deploy: rename enableAllLocalDefaults to deploy.singleHostSwarm
2026-08-30 20:12:16 +02:00
local-defaults.nix
deploy: rename enableAllLocalDefaults to deploy.singleHostSwarm
2026-08-30 20:12:16 +02:00
otel.nix
deploy: move the hive CA's knobs to deploy.hive-controller.tls
2026-08-30 20:52:00 +02:00
stylix-theme.nix
swarm-ui: apply the operator's stylix theme, same as the dashboard already does
2026-08-24 14:28:25 +02:00
swarm-authelia.nix
swarm: remove swarm.ui.domain, serve the UI on the swarm domain
2026-08-31 19:00:52 +02:00
swarm-bao.nix
fix( #3813 ): seal with an RSA-OAEP key, the only mechanism the TPM has
2026-09-01 09:16:04 +02:00
swarm-ca.nix
deploy: move the hive CA's knobs to deploy.hive-controller.tls
2026-08-30 20:52:00 +02:00
swarm-container-resolver.nix
fix( #3363 ): swarm containers write their own resolver file
2026-08-17 17:30:15 +02:00
swarm-controller.nix
swarm: remove swarm.ui.domain, serve the UI on the swarm domain
2026-08-31 19:00:52 +02:00
swarm-grafana.nix
deploy: name the swarm collector swarm-otel, not otel
2026-08-30 04:23:22 +02:00
swarm-nats.nix
deploy: move the hive CA's knobs to deploy.hive-controller.tls
2026-08-30 20:52:00 +02:00
swarm-otel.nix
swarm: extract the name guards, so the module just says what is forbidden
2026-08-31 18:50:15 +02:00
swarm-peers-removed.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm-required-services.nix
deploy: rename enableAllLocalDefaults to deploy.singleHostSwarm
2026-08-30 20:12:16 +02:00
swarm-snapshot-store.nix
refactor( #2862 ): keep the option at services.hyperhive.snapshotStore
2026-07-31 19:03:24 +02:00
swarm-ui.nix
swarm: remove swarm.ui.domain, serve the UI on the swarm domain
2026-08-31 19:00:52 +02:00
swarm-victorialogs.nix
deploy: retention is the store host's decision, not the swarm's
2026-08-30 16:23:48 +02:00
swarm-victoriametrics.nix
deploy: retention is the store host's decision, not the swarm's
2026-08-30 16:23:48 +02:00
swarm-wireguard.nix
docs+nix: fix stale certFingerprint/HYPERHIVE_PEERS references (hyperhive#3294)
2026-08-15 19:56:11 +02:00
swarm.nix
swarm: remove swarm.ui.domain, serve the UI on the swarm domain
2026-08-31 19:00:52 +02:00