docs: a first SSO login makes a human's forge account
setup.md said Swarm SSO creates the operator's forge account, which was not true until the previous commits. It now says how: sign in to the forge once through authelia, then `swarmctl forge make-admin <you>`. sso.md says what that first login does and why ACCOUNT_LINKING is `login`. README, hivectl.md and forge.md drop `hivectl forge create-user`, and the swarmctl README gains `forge make-admin`. Refs #3782
This commit is contained in:
parent
d56d8f2b36
commit
0cbb7db2c0
6 changed files with 62 additions and 33 deletions
|
|
@ -48,8 +48,9 @@ about ten minutes. `swarmctl agent mint-forge-token ruth` skips the wait for
|
|||
the pass. A hive without a swarm secret store has no path to a forge token
|
||||
for ruth at all.
|
||||
|
||||
Swarm SSO creates the human operator's own forge account instead of
|
||||
a manual `hivectl` step — see _Swarm SSO_ below (`swarmctl user add`).
|
||||
Swarm SSO creates the human operator's own forge account: the forge
|
||||
makes it on their first login through authelia, and `swarmctl forge
|
||||
make-admin <you>` then makes it a site admin — see _Swarm SSO_ below.
|
||||
|
||||
### 2 · Gateway (HTTP Basic auth)
|
||||
|
||||
|
|
@ -195,6 +196,22 @@ If an account already exists without it, `user add` refuses rather
|
|||
than amends — adding the group afterwards is `swarmctl user update mara
|
||||
--add-group admins`.
|
||||
|
||||
Then sign in to the forge once through authelia, with that account. That
|
||||
first login creates your forge account, under the same username. Make it
|
||||
a site admin:
|
||||
|
||||
```bash
|
||||
# On the swarm-controller's host. Fails until that first login has happened.
|
||||
swarmctl forge make-admin mara
|
||||
```
|
||||
|
||||
⚠️ **Keep `--email` too.** The forge won't create an account without an
|
||||
email: a subject that has none gets the forge's link-account page and no
|
||||
account. `swarmctl user update mara --email …` fixes it.
|
||||
|
||||
If the forge already has a local account with your username, the first
|
||||
SSO login asks for that account's forge password once, to link the two.
|
||||
|
||||
Detail, including what the password is and why this stays manual:
|
||||
[`swarm/sso.md`](../swarm/sso.md).
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue