docs: a first SSO login makes a human's forge account
setup.md said Swarm SSO creates the operator's forge account, which was not true until the previous commits. It now says how: sign in to the forge once through authelia, then `swarmctl forge make-admin <you>`. sso.md says what that first login does and why ACCOUNT_LINKING is `login`. README, hivectl.md and forge.md drop `hivectl forge create-user`, and the swarmctl README gains `forge make-admin`. Refs #3782
This commit is contained in:
parent
d56d8f2b36
commit
0cbb7db2c0
6 changed files with 62 additions and 33 deletions
|
|
@ -109,3 +109,17 @@ than shared: the controller's own types are private to its binary, this
|
|||
crate does not link it, and there is no wire-type crate between them.
|
||||
Two fields out, two in, both ends validating — a drift shows up as a
|
||||
400 naming the field.
|
||||
|
||||
## `forge make-admin`
|
||||
|
||||
```console
|
||||
# swarmctl forge make-admin mara
|
||||
forge: "mara" is now a site admin
|
||||
```
|
||||
|
||||
`POST /api/forge/users/{name}/admin` on the swarm-controller, over the same
|
||||
socket as `agent create`. It never creates an account: the forge makes a
|
||||
person's on their first login through authelia, and until then this fails
|
||||
saying so. Running it on a site admin changes nothing, and an agent's name is
|
||||
refused. The response shape is mirrored in `src/forge.rs`, for the same
|
||||
reason as `agent create`'s.
|
||||
|
|
|
|||
Loading…
Reference in a new issue