docs: a first SSO login makes a human's forge account

setup.md said Swarm SSO creates the operator's forge account, which was
not true until the previous commits. It now says how: sign in to the
forge once through authelia, then `swarmctl forge make-admin <you>`.
sso.md says what that first login does and why ACCOUNT_LINKING is
`login`. README, hivectl.md and forge.md drop `hivectl forge
create-user`, and the swarmctl README gains `forge make-admin`.

Refs #3782
This commit is contained in:
atlas 2026-09-25 02:11:44 +02:00 • committed by mara
commit 0cbb7db2c0
6 changed files with 62 additions and 33 deletions

View file

@ -48,8 +48,9 @@ about ten minutes. `swarmctl agent mint-forge-token ruth` skips the wait for
the pass. A hive without a swarm secret store has no path to a forge token
for ruth at all.
Swarm SSO creates the human operator's own forge account instead of
a manual `hivectl` step — see _Swarm SSO_ below (`swarmctl user add`).
Swarm SSO creates the human operator's own forge account: the forge
makes it on their first login through authelia, and `swarmctl forge
make-admin <you>` then makes it a site admin — see _Swarm SSO_ below.
### 2 · Gateway (HTTP Basic auth)
@ -195,6 +196,22 @@ If an account already exists without it, `user add` refuses rather
than amends — adding the group afterwards is `swarmctl user update mara
--add-group admins`.
Then sign in to the forge once through authelia, with that account. That
first login creates your forge account, under the same username. Make it
a site admin:
```bash
# On the swarm-controller's host. Fails until that first login has happened.
swarmctl forge make-admin mara
```
⚠️ **Keep `--email` too.** The forge won't create an account without an
email: a subject that has none gets the forge's link-account page and no
account. `swarmctl user update mara --email …` fixes it.
If the forge already has a local account with your username, the first
SSO login asks for that account's forge password once, to link the two.
Detail, including what the password is and why this stays manual:
[`swarm/sso.md`](../swarm/sso.md).