swarm-controller: mint each agent's matrix account with the swarm's token
A `MintAgentMatrixAccount` node creates the agent's account on the swarm's homeserver with the swarm appservice token, stores its token at `swarm/agents/<agent>/matrix/main`, and reads it back with whoami before reporting success. It is a root of agent creation, `after_any` into the deploy, and a five-minute backfill over every agent with a store identity queues the same node — the shape of the forge-token mint. The decision reads the stored token back rather than only checking that one is stored: the swarm and a hive both pin the device `hyperhive-<agent>`, so each login replaces the other's token. A failed read plans nothing, so an outage never rotates every agent's token. `matrixHomeserverUrl` now defaults to the swarm's `chat.` vhost, since the mint is what consults it.
This commit is contained in:
parent
9308752a09
commit
2776e121e5
7 changed files with 626 additions and 36 deletions
|
|
@ -59,6 +59,15 @@ let
|
|||
|
||||
baoWrapperCmd = if baoWrapper == null then "" else (baoWrapper.buildCommand or "");
|
||||
cases = [
|
||||
{
|
||||
# No hive mints an agent's matrix account any more, so a controller that
|
||||
# did not know the homeserver would create every agent without one. The
|
||||
# default is the swarm's own `chat.` vhost, with no operator setting.
|
||||
name = "the controller is told the swarm's homeserver by default";
|
||||
ok =
|
||||
controllerNoStore.systemd.services.swarm-controller.environment.SWARM_CONTROLLER_MATRIX_HOMESERVER_URL
|
||||
or null == "https://chat.t.local";
|
||||
}
|
||||
{
|
||||
# Nothing asserted the PKI script before this, so a third leaf could be
|
||||
# added to it and every case still passed — measured, not assumed: the
|
||||
|
|
|
|||
Loading…
Reference in a new issue