docs: a first SSO login makes a human's forge account
setup.md said Swarm SSO creates the operator's forge account, which was not true until the previous commits. It now says how: sign in to the forge once through authelia, then `swarmctl forge make-admin <you>`. sso.md says what that first login does and why ACCOUNT_LINKING is `login`. README, hivectl.md and forge.md drop `hivectl forge create-user`, and the swarmctl README gains `forge make-admin`. Refs #3782
This commit is contained in:
parent
d56d8f2b36
commit
0cbb7db2c0
6 changed files with 62 additions and 33 deletions
10
README.md
10
README.md
|
|
@ -114,16 +114,18 @@ doesn't go through the broker (built alongside `hive-c0re` when the host
|
|||
module is enabled):
|
||||
|
||||
```sh
|
||||
sudo hivectl forge create-user mara # provisions a forge user
|
||||
sudo hivectl forge create-user mara --password 'hunter2' # … with a fixed password
|
||||
sudo hivectl matrix create-user mara # provisions a matrix user
|
||||
sudo hivectl matrix create-user mara --password-stdin # … reading one line from stdin
|
||||
```
|
||||
|
||||
For a name that's a managed agent, `hivectl` persists the resulting token
|
||||
to that agent's state dir, the same as the boot sweep does. For a
|
||||
non-agent name (e.g. the operator's own forge/matrix account), it prints
|
||||
the token to stdout and writes nothing.
|
||||
non-agent name (for example the operator's own matrix account), it prints the
|
||||
token to stdout and writes nothing.
|
||||
|
||||
A human's first SSO login to the forge makes their forge account, not
|
||||
`hivectl`; `swarmctl forge make-admin <name>` on the swarm-controller's
|
||||
host makes it a site admin.
|
||||
|
||||
## Build / deploy
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue