swarm-controller: own the swarm-wide forge objects; hive-c0re stops creating them
The orgs agent-configs/internal/agents (plus mirror owners), the operators team in agents and agent-configs, the pull-mirrors, internal/docs, internal/knowledge (public, README-seeded) and the agent-configs org avatar are one set per forge. hive-c0re ensured them in its boot sweep, as the core admin, and only on the hive co-located with the forge container. swarm-controller now reconciles them at start and every 5 minutes (forge/objects.rs: observe -> pure plan -> apply). A failed object logs a warn line plus a pass summary and is retried next tick. create_repo ensures the agent-configs org and its operators team first, so a config repo's merge gate never depends on the periodic pass having run. hive-c0re drops ensure_org, SEEDED_ORGS, ensure_mirrors/ensure_mirror_repo, ensure_operators_team, ensure_shared_docs_repo, ensure_knowledge_repo/ set_repo_public, seed_readme, ensure_config_org_avatar and the one-shot knowledge::remove_webhook cleanup, with their now-unused helpers. nix: the mirror list moves from the hive-c0re unit (HYPERHIVE_FORGE_MIRRORS) to the swarm-controller unit (SWARM_CONTROLLER_FORGE_MIRRORS), with an eval warning when mirrors are declared on a host that runs no controller. c0re.orgAvatarPng is renamed to deploy.swarm-controller.configOrgAvatarPng. Refs #3782
This commit is contained in:
parent
85ba45b2de
commit
20419ccd41
18 changed files with 1456 additions and 822 deletions
|
|
@ -69,11 +69,23 @@ fn secret_path() -> std::path::PathBuf {
|
|||
/// tests setting it race — which is not hypothetical here, it is how the
|
||||
/// first version of this module's tests failed.
|
||||
fn secret_path_from(raw: Option<&str>) -> std::path::PathBuf {
|
||||
state_dir_from(raw).join(SECRET_FILE)
|
||||
}
|
||||
|
||||
/// This daemon's state directory, read the same way [`secret_path`] reads
|
||||
/// it. Other state files (the forge avatar marker in
|
||||
/// `crate::forge::objects`) live beside the secret, so both share this one
|
||||
/// reading of `STATE_DIRECTORY`.
|
||||
pub fn state_dir() -> std::path::PathBuf {
|
||||
state_dir_from(std::env::var("STATE_DIRECTORY").ok().as_deref())
|
||||
}
|
||||
|
||||
fn state_dir_from(raw: Option<&str>) -> std::path::PathBuf {
|
||||
let dir = raw
|
||||
.and_then(|raw| raw.split(':').next())
|
||||
.filter(|first| !first.is_empty())
|
||||
.unwrap_or(DEFAULT_STATE_DIR);
|
||||
std::path::PathBuf::from(dir).join(SECRET_FILE)
|
||||
std::path::PathBuf::from(dir)
|
||||
}
|
||||
|
||||
/// Load the swarm's webhook HMAC secret, generating and persisting it if the
|
||||
|
|
|
|||
Loading…
Reference in a new issue