docs: a first SSO login makes a human's forge account

setup.md said Swarm SSO creates the operator's forge account, which was
not true until the previous commits. It now says how: sign in to the
forge once through authelia, then `swarmctl forge make-admin <you>`.
sso.md says what that first login does and why ACCOUNT_LINKING is
`login`. README, hivectl.md and forge.md drop `hivectl forge
create-user`, and the swarmctl README gains `forge make-admin`.

Refs #3782
This commit is contained in:
atlas 2026-09-25 02:11:44 +02:00 • committed by mara
commit 0cbb7db2c0
6 changed files with 62 additions and 33 deletions

View file

@ -109,3 +109,17 @@ than shared: the controller's own types are private to its binary, this
crate does not link it, and there is no wire-type crate between them.
Two fields out, two in, both ends validating — a drift shows up as a
400 naming the field.
## `forge make-admin`
```console
# swarmctl forge make-admin mara
forge: "mara" is now a site admin
```
`POST /api/forge/users/{name}/admin` on the swarm-controller, over the same
socket as `agent create`. It never creates an account: the forge makes a
person's on their first login through authelia, and until then this fails
saying so. Running it on a site admin changes nothing, and an agent's name is
refused. The response shape is mirrored in `src/forge.rs`, for the same
reason as `agent create`'s.